CVE-2012-4792
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Dec 30, 2012
Updated: Dec 19, 2024
CWE ID 416
Summary
CVE-2012-4792 is a use-after-free vulnerability affecting Microsoft Internet Explorer 6 through 8. Maliciously crafted websites can trigger this issue by accessing an object that was not properly allocated or has been deleted. The CDwnBindInfo object has been identified as being exploited in the wild in December 2012, enabling attackers to execute arbitrary code remotely. This vulnerability poses a significant risk to users browsing untrusted websites and should be addressed by applying the available Microsoft patch.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Internet Explorer
Affected Vendors
- Microsoft