PT-2012-3617 · Microsoft · Internet Explorer

CVE-2012-1876

·

Publicado

2012-06-12

·

Atualizado

2023-12-07

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 6 through 9, and 10 Consumer Preview
Description The issue arises from improper handling of objects in memory, allowing remote attackers to execute arbitrary code by attempting to access a nonexistent object. This leads to a heap-based buffer overflow, potentially corrupting memory in a way that enables an attacker to execute arbitrary code in the context of the current user. The vulnerability was demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
Recommendations For Microsoft Internet Explorer versions 6 through 9, and 10 Consumer Preview, update to a newer version to mitigate the risk. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-1876
ZDI-12-093

Produtos afetados

Internet Explorer