CVE-2012-2523

Description

Integer overflow in Microsoft Internet Explorer 8 and 9, JScript 5.8, and VBScript 5.8 on 64-bit platforms allows remote attackers to execute arbitrary code by leveraging an incorrect size calculation during object copying, aka JavaScript Integer Overflow Remote Code Execution Vulnerability.

Risk Information

Base Score
7.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
EPSS Score
Exploitation Probability
64.663

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Security Update for Internet Explorer for Windows XP (KB2722913)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2722913)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2722913)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2722913)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2722913)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2722913)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2722913)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2722913)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2722913)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2722913) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2722913) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2722913) for SP1Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2722913) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2722913)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2722913)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2722913) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2722913) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2722913) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2722913)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2722913)Windows
ms12-056: vulnerability in jscript and vbscript engines could allow remote code execution: august 14, 2012 for Windows XP x64 Edition (KB2706045)Windows
ms12-056: vulnerability in jscript and vbscript engines could allow remote code execution: august 14, 2012 for Windows Server 2003 x64 Edition (KB2706045)Windows
ms12-056: vulnerability in jscript and vbscript engines could allow remote code execution: august 14, 2012 for Windows Vista for x64-based Systems (KB2706045)Windows
ms12-056: vulnerability in jscript and vbscript engines could allow remote code execution: august 14, 2012 for Windows Server 2008 x64 Edition (KB2706045)Windows
ms12-056: vulnerability in jscript and vbscript engines could allow remote code execution: august 14, 2012 for Windows 7 for x64-based Systems (KB2706045)Windows
ms12-056: vulnerability in jscript and vbscript engines could allow remote code execution: august 14, 2012 for Windows 7 for x64-based Systems (KB2706045) for SP1Windows
ms12-056: vulnerability in jscript and vbscript engines could allow remote code execution: august 14, 2012 for Windows Server 2008 R2 x64 Edition (KB2706045)Windows
ms12-056: vulnerability in jscript and vbscript engines could allow remote code execution: august 14, 2012 for Windows Server 2008 R2 x64 Edition (KB2706045) for SP1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-12267Cumulative Security Update for Internet Explorer for Windows XP (KB2722913)
PATCH-12268Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2722913)
PATCH-12270Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2722913)
PATCH-12271Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2722913)
PATCH-12273Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2722913)
PATCH-12274Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2722913)
PATCH-12275Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2722913)
PATCH-12276Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2722913)
PATCH-12277Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2722913)
PATCH-12278Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2722913)
PATCH-12279Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2722913)
PATCH-12280Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2722913)
PATCH-12281Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2722913)
PATCH-12282Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2722913)
PATCH-12283Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2722913)
PATCH-12284Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2722913)
PATCH-12285Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2722913)
PATCH-12286Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2722913)
PATCH-12287Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2722913)
PATCH-12288Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2722913)
PATCH-12289Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2722913)
PATCH-12290Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2722913)
PATCH-12291Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2722913)
PATCH-12292Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2722913)
PATCH-12293Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2722913)
PATCH-12294Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2722913)
PATCH-12295Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2722913)
PATCH-12296Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2722913)
PATCH-12297Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2722913)
PATCH-12298Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2722913)
PATCH-12299Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2722913)
PATCH-12300Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2722913)
PATCH-12301Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2722913)
PATCH-12375Security Update for Windows XP x64 Edition (KB2706045)
PATCH-12376Security Update for Windows Server 2003 x64 Edition (KB2706045)
PATCH-12377Security Update for Windows Vista for x64-based Systems (KB2706045)
PATCH-12378Security Update for Windows Server 2008 x64 Edition (KB2706045)
PATCH-12379Security Update for Windows 7 for x64-based Systems (KB2706045)
PATCH-12380Security Update for Windows 7 for x64-based Systems (KB2706045)
PATCH-12381Security Update for Windows Server 2008 R2 x64 Edition (KB2706045)
PATCH-12382Security Update for Windows Server 2008 R2 x64 Edition (KB2706045)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234