CVE-2012-4969

Description

Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
91.84

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Security Update for Internet Explorer for Windows XP (KB2744842)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2744842)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2744842)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2744842)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2744842)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2744842)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2744842)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2744842)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2744842)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2744842) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2744842) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2744842) for SP1Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2744842) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2744842)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2744842)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2744842) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2744842) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2744842) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2744842)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2744842)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-12416Cumulative Security Update for Internet Explorer for Windows XP (KB2744842)
PATCH-12417Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2744842)
PATCH-12419Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2744842)
PATCH-12420Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2744842)
PATCH-12422Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2744842)
PATCH-12423Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2744842)
PATCH-12424Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2744842)
PATCH-12425Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2744842)
PATCH-12426Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2744842)
PATCH-12427Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2744842)
PATCH-12428Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2744842)
PATCH-12429Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2744842)
PATCH-12430Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2744842)
PATCH-12431Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2744842)
PATCH-12432Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2744842)
PATCH-12433Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2744842)
PATCH-12434Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2744842)
PATCH-12435Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2744842)
PATCH-12436Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2744842)
PATCH-12437Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2744842)
PATCH-12438Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2744842)
PATCH-12439Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2744842)
PATCH-12440Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2744842)
PATCH-12441Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2744842)
PATCH-12442Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2744842)
PATCH-12443Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2744842)
PATCH-12444Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2744842)
PATCH-12445Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2744842)
PATCH-12446Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2744842)
PATCH-12447Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2744842)
PATCH-12448Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2744842)
PATCH-12449Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2744842)
PATCH-12450Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2744842)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234