CVE-2012-1889

Description

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
92.781

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows XP (KB2719985)Windows
Security Update for Windows Server 2003 (KB2719985)Windows
Security Update for Windows Vista (KB2719985)Windows
Security Update for Windows Server 2008 (KB2719985)Windows
Security Update for Windows 7 (KB2719985) x86 based systemsWindows
Security Update for Windows 7 (KB2719985) x86 based systems for SP1Windows
Security Update for Windows XP x64 Edition (KB2719985)Windows
Security Update for Windows Server 2003 x64 Edition (KB2719985)Windows
Security Update for Windows Vista for x64-based Systems (KB2719985)Windows
Security Update for Windows Server 2008 x64 Edition (KB2719985)Windows
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. for Windows 7 for x64-based Systems (KB2719985)Windows
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. for Windows 7 for x64-based Systems (KB2719985) for SP1Windows
Security Update for Windows 7 for x64-based Systems (KB2719985)Windows
Security Update for Windows 7 for x64-based Systems (KB2719985) for SP1Windows
Security Update for Microsoft XML Core Services 4.0 Service Pack 3 (KB2721691)Windows
Security Update for Microsoft XML Core Services 4.0 Service Pack 3 for x64-based Systems (KB2721691)Windows
Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB2721693)Windows
Security Update for Microsoft XML Core Services 6.0 Service Pack 2 for x64-based Systems (KB2721693)Windows
Security Update for Microsoft Office 2003 (KB2687324)Windows
Security Update for Microsoft Office 2007 suites (KB2596856)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-12106Security Update for Windows Server 2003 (KB2719985)
PATCH-12107Security Update for Windows Vista (KB2719985)
PATCH-12108Security Update for Windows Server 2008 (KB2719985)
PATCH-12109Security Update for Windows 7 (KB2719985)
PATCH-12110Security Update for Windows 7 (KB2719985)
PATCH-12111Security Update for Windows XP x64 Edition (KB2719985)
PATCH-12112Security Update for Windows Server 2003 x64 Edition (KB2719985)
PATCH-12113Security Update for Windows Vista for x64-based Systems (KB2719985)
PATCH-12114Security Update for Windows Server 2008 x64 Edition (KB2719985)
PATCH-12115Security Update for Windows 7 for x64-based Systems (KB2719985)
PATCH-12116Security Update for Windows 7 for x64-based Systems (KB2719985)
PATCH-12117Security Update for Windows 7 for x64-based Systems (KB2719985)
PATCH-12118Security Update for Windows 7 for x64-based Systems (KB2719985)
PATCH-12119Security Update for Microsoft XML Core Services 4.0 Service Pack 3 (KB2721691)
PATCH-12120Security Update for Microsoft XML Core Services 4.0 Service Pack 3 for x64-based Systems (KB2721691)
PATCH-12121Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB2721693)
PATCH-12122Security Update for Microsoft XML Core Services 6.0 Service Pack 2 for x64-based Systems (KB2721693)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234