CVE-2012-4787

Description

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly initialized or (2) is deleted, aka Improper Ref Counting Use After Free Vulnerability.

Risk Information

Base Score
9.0
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
36.178

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Security Update for Internet Explorer for Windows XP (KB2761465)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2761465)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2761465)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2761465)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2761465)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2761465)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2761465)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2761465)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2761465)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2761465) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2761465) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2761465) for SP1Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2761465) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2761465)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2761465)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2761465) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2761465) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2761465) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2761465)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2761465)Windows
Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2761465)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-12741Cumulative Security Update for Internet Explorer for Windows XP (KB2761465)
PATCH-12742Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2761465)
PATCH-12744Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2761465)
PATCH-12745Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2761465)
PATCH-12747Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2761465)
PATCH-12748Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2761465)
PATCH-12749Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2761465)
PATCH-12750Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2761465)
PATCH-12751Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2761465)
PATCH-12752Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2761465)
PATCH-12753Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2761465)
PATCH-12754Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2761465)
PATCH-12755Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2761465)
PATCH-12756Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2761465)
PATCH-12757Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2761465)
PATCH-12758Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2761465)
PATCH-12759Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2761465)
PATCH-12760Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2761465)
PATCH-12761Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2761465)
PATCH-12762Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2761465)
PATCH-12763Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2761465)
PATCH-12764Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2761465)
PATCH-12765Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2761465)
PATCH-12766Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2761465)
PATCH-12767Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2761465)
PATCH-12768Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2761465)
PATCH-12769Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2761465)
PATCH-12770Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2761465)
PATCH-12771Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2761465)
PATCH-12772Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2761465)
PATCH-12773Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2761465)
PATCH-12774Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2761465)
PATCH-12775Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2761465)
PATCH-12777Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2761465)
PATCH-12778Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2761465)
PATCH-12779Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2761465)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234