Vulnerability CVE-2012-1879


Published: 2012-06-12   Modified: 2012-06-13

Description:
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access an undefined memory location, aka "insertAdjacentText Remote Code Execution Vulnerability."

See advisories in our WLB2 database:
Topic
Author
Date
High
Microsoft Internet Explorer insertAdjacentText Remote Code Execution
Anonymous
21.12.2012

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Microsoft -> IE 

 References:
http://www.us-cert.gov/cas/techalerts/TA12-164A.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-037
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15588

Copyright 2024, cxsecurity.com

 

Back to Top