CVE-2012-2290: Code Injection
Published Oct 18, 2012
·Updated
The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel.
Affected Software
3 affected components
EMC NetWorker Module for Microsoft Applications=2.2.1
EMC NetWorker Module for Microsoft Applications=2.3
EMC NetWorker Module for Microsoft Applications=2.4
Event History
Oct 18, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2290?
CVE-2012-2290 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2012-2290?
To fix CVE-2012-2290, upgrade EMC NetWorker Module for Microsoft Applications to version 2.3 build 122 or 2.4 build 375 or later.
3
What versions of EMC NetWorker Module for Microsoft Applications are affected by CVE-2012-2290?
Versions 2.2.1, 2.3 before build 122, and 2.4 before build 375 of EMC NetWorker Module for Microsoft Applications are affected by CVE-2012-2290.
4
Can CVE-2012-2290 be exploited remotely?
Yes, CVE-2012-2290 can be exploited remotely by attackers through crafted TCP messages.
5
What type of vulnerability is CVE-2012-2290?
CVE-2012-2290 is a remote code execution vulnerability.