CVE-2012-1537

Scores

EPSS

0.622medium62.2%
0%20%40%60%80%100%

Percentile: 62.2%

CVSS

9.3critical2.0
0246810

CVSS Score: 9.3/10

All CVSS Scores

CVSS 2.0
9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted Office document, aka “DirectPlay Heap Overflow Vulnerability.”

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-119

Vulnerable Software (4)

Type: Configuration

Vendor: *

Product: directx

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:microsoft:directx:10.1:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"  ...

Source: nvd

Type: Configuration

Vendor: *

Product: directx

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:microsoft:directx:11.0:*:*:*:*:*:*:*",          "vulnerable": true        },        {          "cpe23uri": "...

Source: nvd

Type: Configuration

Vendor: *

Product: directx

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:microsoft:directx:9.0:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"   ...

Source: nvd

Type: Configuration

Vendor: *

Product: directx

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:microsoft:directx:10.0:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"  ...

Source: nvd

End of list