Executive brief
Microsoft XML Core Services (MSXML) versions 3.0 through 6.0 contain a memory corruption vulnerability due to improper access of uninitialized memory locations. A remote attacker can exploit this by enticing a user to visit a specially crafted website, leading to arbitrary code execution or a denial of service.
Affected products
- Microsoft XML Core Services 3.0, 4.0, 5.0, 6.0
Timeline
- 2012-06-12: advisory: Microsoft Security Advisory 2719615 published
- 2012-07-10: patched: Microsoft Security Bulletin MS12-043 released
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-06-08: exploited: Confirmed exploited in the wild per CISA KEV entry