CVE-2012-5896: Quest Intrust
High severity, CVSS 10.0. EPSS: 69.4% chance of exploitation in the next 30 days.
The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Add method, which allows remote attackers to execute arbitrary code via a memory address in the first argument, related to an "uninitialized pointer."
Affected products
- Quest Intrust: up to and including 10.4.0.853; version 10.1 only; version 10.2.5 only; version 10.3 only; version 10.4 only
Published 2012-11-17. Last modified 2026-06-16.