ID:4360 - Exploit for Arbitrary file upload in Lenovo ThinkManagement Console - CVE-2012-1195

 
Main Vulnerability Database Exploits ID:4360 - Exploit for Arbitrary file upload in Lenovo ThinkManagement Console - CVE-2012-1195

ID:4360 - Exploit for Arbitrary file upload in Lenovo ThinkManagement Console - CVE-2012-1195

Published: August 11, 2020


Vulnerability identifier: #VU44262
Vulnerability risk: Medium
CVE-ID: CVE-2012-1195
CWE-ID: CWE-434
Exploitation vector: Remote access
Vulnerable software:
Lenovo ThinkManagement Console

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to insufficient validation of user-supplied input when uploading files in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service. A remote attacker can upload and execute arbitrary file on the server via the a PutUpdateFileCore command in a RunAMTCommand SOAP request.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.