CVE-2012-2421: Intuit Quickbooks

Low severity, CVSS 1.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Absolute path traversal vulnerability in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to read arbitrary files in ZIP archives via a full pathname in the URI.

Affected products

  • Intuit Quickbooks: version 2009 only; version 2010 only; version 2011 only; version 2012 only

Published 2012-04-25. Last modified 2026-06-16.