cbcvebase.
CVE-2012-1889
published 2012-06-13

CVE-2012-1889: Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a…

PriorityP189high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-06-22
Exploited in the wild
EPSS
83.64%
99.7th percentile
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

Affected

4 ranges
VendorProductVersion rangeFixed in
microsoftxml_core_services
microsoftxml_core_services
microsoftxml_core_services
microsoftxml_core_services

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://www.xxxxxxxcurling.com/Results/cx/magma/iframe.js
domaintorontocurling.com
domainJs.users.51.la
domainWeb1.51.la
snort
SID 23142
snort
SID 23143
snort
SID 23144
snort
SID 23145
snort
SID 23146
  • Exploit delivery involved iframe injection into compromised sites redirecting to a dedicated exploit server; monitor for suspicious iframe injections pointing to external domains serving CAB/JAR files
  • A Metasploit module for CVE-2012-1889 was released June 15, 2012, significantly broadening the attacker base; monitor for Metasploit-generated exploit traffic against MSXML
  • Group 72 / Axiom domains follow a pattern of naming after intended victims (companyname.attackerdomain.com or companyacronym.attackerdomain.com); use this naming pattern for proactive domain hunting
  • DeputyDog RAT used campaign codes 'kumanichi' and 'moon'; hunt for these strings in network traffic or malware samples
  • ClamAV signature Win.Trojan.HyDraq covers Hydraq/9002 RAT/McRAT/Naid malware associated with CVE-2012-1889 exploitation campaigns
  • Google was issuing warnings to potential victims in Gmail about CVE-2012-1889 exploitation at least since June 5, 2012, indicating early targeted exploitation before public disclosure
  • ·The Recorded Future report lists two slightly different IP addresses for the same C&C node in different parts of the article (58.64.143.244 vs 58.65.143.244); verify the correct address before blocking
  • ·Snort SIDs 23142–23146 for CVE-2012-1889 are described as 'extremely generic in relation to the vulnerability' and were designed to cover all known and future exploit variants; tune carefully to avoid false positives
  • ·The Zscaler blog post for CVE-2012-1889 appears to have had most of its technical content stripped from the scraped version; only two IOC domains (Js.users.51.la and Web1.51.la:82) were recoverable

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.