CVE-2012-3022
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
16/04/2013
Last modified:
11/04/2025
Description
The SaveToFile method in a certain ActiveX control in TrendDisplay.dll in Canary Labs TrendLink 9.0.2.27051 and earlier does not properly restrict the creation of files, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted web site.
Impact
Base Score 2.0
8.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:canarylabs:trendlink:*:*:*:*:*:*:*:* | 9.0.2.27051 (including) |
To consult the complete list of CPE names with products and versions, see this page