CVE-2012-4969
CVSS 2.0 Score 9.3 of 10 (high)
Details
Published Sep 18, 2012
Updated: Dec 20, 2024
Summary
CVE-2012-4969 is a use-after-free vulnerability impacting the CMshtmlEd::Exec function in mshtml.dll, which is part of Microsoft Internet Explorer 6 through 9. Attackers can leverage this issue to execute arbitrary code by creating a specially crafted website. This vulnerability was exploited in the wild in September 2012, emphasizing its seriousness and the need for users to apply available patches promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Internet Explorer
Affected Vendors
- Microsoft