Overview
Intuit QuickBooks 2009 through 2012 have been reported to contain a file disclosure and heap corruption vulnerability.
Description
Derek Soeder's vulnerability report states the following: Intuit Help System Protocol File Retrieval |
Impact
An attacker may be able to retrieve sensitive files or run arbitrary code. |
Solution
QuickBooks 2008 through 2012 will automatically update to address this vulnerability. If you are unable to apply the latest updates, please consider the following workaround. |
Disable the Intuit Help System protocol |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 5 | AV:A/AC:--/Au:N/C:C/I:C/A:P |
Temporal | 3.6 | E:U/RL:W/RC:UC |
Environmental | 3.6 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Derek Soeder for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | None |
Date Public: | 2012-03-30 |
Date First Published: | 2012-04-02 |
Date Last Updated: | 2012-05-21 18:24 UTC |
Document Revision: | 17 |