CVE-2012-2421
lowCVSS v3 Base Score
1.8
AV:A/AC:H/Au:N/C:P/I:N/A:N
EPSS Score
0.1%
Exploitation probability in 30 days
Top 77% most likely to be exploited
Attack Characteristics
Attack Vector
Adjacent
Attack Complexity
High
Confidentiality
P
Integrity
None
Availability
None
Published: April 25, 2012 (5132 days ago)
Last Modified: April 29, 2026
Vendor: Microsoft
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
Absolute path traversal vulnerability in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to read arbitrary files in ZIP archives via a full pathname in the URI.
CWE
CWE-22Affected Products
intuit quickbooks