Vulnerability record · CVE-2012-3274 · published 6 December 2012
CVE-2012-3274: HP Intelligent Management Center UAM stack buffer overflow via log data
Hp · Intelligent Management Center
HP Intelligent Management Center (IMC) before 5.1 E0101P01 contains a stack-based buffer overflow in uam.exe in the User Access Manager component, triggered through vectors related to log data. A remote, unauthenticated attacker can overflow the buffer and execute arbitrary code, making this a full-compromise flaw in an enterprise management platform.
Description
Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (IMC) before 5.1 E0101P01 allows remote attackers to execute arbitrary code via vectors related to log data.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, plus very high EPSS, warrants critical handling despite no confirmed in-the-wild exploitation.
What it is
HP Intelligent Management Center (IMC) before 5.1 E0101P01 contains a stack-based buffer overflow in uam.exe in the User Access Manager component, triggered through vectors related to log data. A remote, unauthenticated attacker can overflow the buffer and execute arbitrary code, making this a full-compromise flaw in an enterprise management platform.
Impact
An attacker gains remote code execution on the IMC server, which can lead to full control of the host and the managed network infrastructure it administers.
Attack surface
The vulnerability is network-reachable (AV:N) with low complexity and no authentication required (Au:N), so it can be triggered by sending crafted log-related data to the UAM component. No user interaction is indicated by the vector.
Exploitation
Not listed in CISA KEV and no reference tags indicate a public exploit, but EPSS is 0.61762 (99.1st percentile), indicating a high modeled likelihood of exploitation activity.
What to do
- Apply the HP fix by upgrading IMC to 5.1 E0101P01 or later; this is the only definitive remediation.
- If patching is delayed, restrict network access to the UAM component and IMC management interfaces to trusted administrative networks only.
- Segment the IMC server from general user and internet-facing networks to limit reachability of the vulnerable service.
- Monitor HP advisories and the ZDI advisory for updated guidance or workarounds.
- Treat the IMC host as high-value and enforce least privilege on any accounts or services that can reach it.
Detection
- Monitor for crashes or abnormal termination of uam.exe on IMC hosts, which may indicate overflow attempts.
- Inspect network traffic to the UAM service for oversized or malformed log-data payloads.
- Alert on unexpected child processes or command execution spawned by uam.exe.
- Review IMC host logs for anomalous access to the UAM component from untrusted source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-3274 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-3274), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.