CVE-2012-2424: Intuit Quickbooks

Low severity, CVSS 1.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a URI that lacks a required delimiter.

Affected products

  • Intuit Quickbooks: version 2009 only; version 2010 only; version 2011 only; version 2012 only

Published 2012-04-25. Last modified 2026-06-16.