Overview
Intuit QuickBooks 2009 through 2012 have been reported to contain a file disclosure and heap corruption vulnerability.
Description
Derek Soeder's vulnerability report states the following: Intuit Help System Protocol File Retrieval |
Impact
An attacker may be able to retrieve sensitive files or run arbitrary code. |
Solution
QuickBooks 2008 through 2012 will automatically update to address this vulnerability. If you are unable to apply the latest updates, please consider the following workaround. |
Disable the Intuit Help System protocol |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | 5 | AV:A/AC:--/Au:N/C:C/I:C/A:P |
| Temporal | 3.6 | E:U/RL:W/RC:UC |
| Environmental | 3.6 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Derek Soeder for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
| CVE IDs: | None |
| Date Public: | 2012-03-30 |
| Date First Published: | 2012-04-02 |
| Date Last Updated: | 2012-05-21 18:24 UTC |
| Document Revision: | 17 |