CVE-2012-5896

critical
Published 2012-11-17 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Add method, which allows remote attackers to execute arbitrary code via a memory address in the first argument, related to an "uninitialized pointer."

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/48566

Application impact

VendorProductVersionsFixed
questintrust{"endIncluding":"10.4.0.853"}
questintrust10.1
questintrust10.2.5
questintrust10.3
questintrust10.4

References

Verify integrity in audit chain (admin only). AS-IS.