CVE-2012-2515: Emc Captiva Quickscan Pro

High severity, CVSS 9.3. EPSS: 27.6% chance of exploitation in the next 30 days.

Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EMC Captiva Quickscan Pro 4.6 SP1; GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; GE Intelligent Platforms Proficy HMI/SCADA iFIX 5.0 and 5.1; GE Intelligent Platforms Proficy Pulse 1.0; GE Intelligent Platforms Proficy Batch Execution 5.6; GE Intelligent Platforms SI7 I/O Driver 7.20 through 7.42; and other products, allow remote attackers to execute arbitrary code via a long string in the second argument to the (1) JumpMappedID or (2) JumpURL method.

Affected products

  • Emc Captiva Quickscan Pro: version 4.6 only
  • Emc Documentum Applicationxtender Desktop: version 5.4 only
  • Ge Intelligent Platforms Proficy Batch Execution: version 5.6 only
  • Ge Intelligent Platforms Proficy Historian: version 3.1 only; version 3.5 only; version 4.0 only; version 4.5 only
  • Ge Intelligent Platforms Proficy Hmi/scada Ifix: version 5.0 only; version 5.1 only
  • Ge Intelligent Platforms Proficy Pulse: version 1.0 only
  • Ge Intelligent Platforms SI7 I/o Driver: version 7.20 only; version 7.42 only

Published 2012-07-05. Last modified 2026-06-16.