CVE-2012-5897: Quest Intrust

High severity, CVSS 9.3. EPSS: 3.8% chance of exploitation in the next 30 days.

The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.

Affected products

  • Quest Intrust: up to and including 10.4.0.853; version 10.1 only; version 10.2.5 only; version 10.3 only; version 10.4 only

Published 2012-11-17. Last modified 2026-06-16.