CVE-2012-1889

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jun 13, 2012
Updated: Dec 19, 2024
CWE ID 787

Summary

CVE-2012-1889 is a memory corruption vulnerability affecting Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0. Uninitialized memory locations are accessed by these software versions, leading to arbitrary code execution or denial of service attacks. Malicious websites can exploit this vulnerability by sending specially crafted data to the affected software, allowing attackers to execute their own code on vulnerable systems. This issue poses a significant risk to organizations and individuals using the susceptible software versions, necessitating immediate patching to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft XML Core Services

Affected Vendors

  • Microsoft