Junglewise Threat Intelligence

CVE-2012-1889: Microsoft XML Core Services Memory Corruption Vulnerability

CVE-2012-1889 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Technologies: Microsoft XML Core Services. Vendors: Microsoft.

Executive brief

Microsoft XML Core Services (MSXML) versions 3.0 through 6.0 contain a memory corruption vulnerability due to improper access of uninitialized memory locations. A remote attacker can exploit this by enticing a user to visit a specially crafted website, leading to arbitrary code execution or a denial of service.

Affected products

  • Microsoft XML Core Services 3.0, 4.0, 5.0, 6.0

Timeline

  • 2012-06-12: advisory: Microsoft Security Advisory 2719615 published
  • 2012-07-10: patched: Microsoft Security Bulletin MS12-043 released
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-08: exploited: Confirmed exploited in the wild per CISA KEV entry

Related threats