Remote Code Execution Risk in IBM SPSS SamplePower ActiveX Control
CVE-2012-0189

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
18 January 2012

Summary

The VsVIEW6 ActiveX control in IBM SPSS SamplePower 3.0 contains multiple unspecified vulnerabilities in the PrintFile and SaveDoc methods. These flaws permit remote attackers to exploit crafted HTML documents, potentially enabling the execution of arbitrary code on the affected system. Users of this product are advised to review their configurations and apply any available updates to mitigate these risks.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.