BDU:2022-04046

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

9.6critical3.x
0246810

CVSS Score: 9.6/10

All CVSS Scores

CVSS 3.x
9.6

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CVSS 2.0
9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

Уязвимость реализации элемента управления «TabStrip» компонента MSCOMCTL.OCX пакета программ Microsoft Office, системы управления реляционными базами данных Microsoft SQL Server, программного средства для систем электронной коммерции Microsoft Commerce Server, среды разработки систем баз данных Microsoft Visual FoxPro связана с ошибками управления генерацией кода. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, выполнить произвольный код с помощью специально созданного вредоносного файла или специально созданной вредоносной ссылки

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

bdu

Related Vulnerabilities

Exploits

Exploit ID: BDU:2022-04046

Source: bdu_exploit

URL: https://bdu.fstec.ru/vul

Recommendations

Source: bdu

Использование рекомендаций:
https://docs.microsoft.com/ru-ru/security-updates/securitybulletins/2012/ms12-060

URL: https://bdu.fstec.ru/vul/2022-04046

Vulnerable Software (17)

Type: Configuration

Vendor: microsoft corp

Product: microsoft commerce server

Operating System: * *

Trait:
{  "version_exact": "2002 SP4"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft commerce server

Operating System: * *

Trait:
{  "version_exact": "2007 SP2"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft commerce server

Operating System: * *

Trait:
{  "version_exact": "2009"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft commerce server

Operating System: * *

Trait:
{  "version_exact": "2009 R2"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft host integration server

Operating System: * *

Trait:
{  "version_exact": "2004 SP1"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft office

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft office 2003 service pack 3

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft office 2007 service pack 2

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft office 2007 service pack 3

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft office 2010 service pack 1

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft sql server

Operating System: * *

Trait:
{  "version_exact": "2000"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft sql server

Operating System: * *

Trait:
{  "version_exact": "2008 R2"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft sql server

Operating System: * *

Trait:
{  "version_exact": "2008"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft sql server

Operating System: * *

Trait:
{  "version_exact": "2005"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft visual basic

Operating System: * *

Trait:
{  "version_exact": "6.0 Runtime"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: visual foxpro

Operating System: * *

Trait:
{  "version_exact": "8.0 SP1"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: visual foxpro

Operating System: * *

Trait:
{  "version_exact": "9.0 SP2"}

Source: bdu

End of list