3 ms·
There's a typo in the CVE number. It's: CVE-2012-0158 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0158 http://www.cve.mitre.org/cgi-bin/cvename.
by terminado 11y ago
There's a typo in the CVE number. It's: CVE-2012-0158
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0158 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0...
...and how is this not a Windows vulnerability, and instead Java?
- Someone1234 11y agoMy guess would be that Java continues to run an unpatched copy of MSCOMCTL.OCX. If you look at the CVE-2012-0158 patches[0] you'll notice that Microsoft had to patch a lot of software individually, I guess Java just was never fixed. So it is a Java issue only in the sense that Oracle needs to update it. Obviously the original "bad code" was from Microsoft. [0] https://technet.microsoft.com/en-us/library/security/ms12-027.aspx https://technet.microsoft.com/en-us/library/security/ms12-02... [1] https://community.emc.com/community/connect/rsaxchange/netwitness/blog/2014/02/12/triaging-malicious-microsoft-office-documents-cve-2012-0158 https://community.emc.com/community/connect/rsaxchange/netwi...
- ackalker 11y agoIsn't the "Malicious Software Removal Tool" from Microsoft supposed to scan for such things? Obviously it isn't a full-fledged virus scanner, but I would expect scanning the system for outdated DLLs and such to be well within its reach.
- Someone1234 11y agoAs far as I know the MSRT is just a virus and or malware scanner. At the moment looking for old binaries it beyond its scope. But that could change. The closest thing to that is this, Securia PSI: https://secunia.com/vulnerability_scanning/personal/ https://secunia.com/vulnerability_scanning/personal/