← back
CVE-2012-0013

CVE-2012-0013

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 74%
from disclosure to weapon4 days
Published on NVDJan 10
1st PoC+4d
metasploitJan 10
exploitation probability
74%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.