CVE-2012-10043 describes a critical stack-based buffer overflow in ActFax Server version 4.32, specifically within the "Import Users from File" functionality of its client interface. This vulnerability arises from inadequate validation of tab-delimited fields in .exp files, leading to unsafe use of strcpy() during CSV parsing. With a CVSS score of 9.3, it carries a high severity, allowing an attacker to achieve arbitrary code execution and full system compromise by crafting a malicious .exp file and tricking a user into importing it. While user interaction is required, a Metasploit module exists, indicating readily available exploit code, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ActFax | Server | 4.32CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.9 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.3 Security Researcher mentions.
Remediation records are not available for this CVE.