CVE-2012-4787Use After Free in Microsoft Internet Explorer

Severity
9.0CRITICALNVD
EPSS
36.2%
top 2.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 12
Latest updateMay 13

Description

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly initialized or (2) is deleted, aka "Improper Ref Counting Use After Free Vulnerability."

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 2.2 | Impact: 6.0

Affected Packages1 packages

🔴Vulnerability Details

1
GHSA
GHSA-ccxg-v3q3-fr8c: Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that tri2022-05-13

🕵️Threat Intelligence

1
Zscaler
Zscaler Protects against Microsoft's Patch Cycle | Round 2

📐Framework References

1
CWE
Improper Update of Reference Count
CVE-2012-4787 — Use After Free in Microsoft | cvebase