Vulnerability Report

CVE-2012-5382

Title: Zend Zend Server Auth Bypass

Auth Bypass

Proof Of Concept

PoC Available for CVE-2012-5382

CWE Category NVD-CWE-noinfo
Published Date Oct 11, 2012
Modified Date Jun 16, 2026
Exploit Status Available
Score 6.0 CVSS v2.0
Exploit Probability (EPSS)
0.87%

Vulnerability Summary

CVE-2012-5382: Untrusted search path vulnerability in the installation functionality in Zend Server 5.6.0 SP4, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the C:\Zend\ZendServer\share\ZendFramework\bin directory, which may be added to the PATH system environment variable by an administrator, as demonstrated by a Trojan horse wlbsctrl.dll file used by the "IKE and AuthIP IPsec Keying Modules" system service in Windows Vista SP1, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 Release Preview. NOTE: CVE disputes this issue because the choice of C:\ (and the resulting unsafe PATH) is established by an administrative action that is not a default part of the Zend Server installation

CVSS v2.0
Source Entity [email protected]
Severity MEDIUM
6.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:L/AC:H/Au:S/C:C/I:C/A:C

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2012-5382 Exploits & PoCs (Proof Of Concept)

Exploit-DB https://www.exploit-db.com/exploits/28130
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:L/AC:H/Au:S/C:C/I:C/A:C

Affected Stack

No specific products linked.