Junglewise Threat Intelligence

CVE-2012-4792: Microsoft Internet Explorer Use-After-Free Vulnerability

CVE-2012-4792 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-07-23

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code. The flaw is triggered when a crafted website causes the browser to access a CDwnBindInfo object that was either improperly allocated or previously deleted.

Affected products

  • Microsoft Internet Explorer 6 through 8

Timeline

  • 2012-12: exploited: Exploited in the wild in December 2012.
  • 2012-12-29: disclosed: Initial public reports of the zero-day vulnerability.
  • 2012-12-31: patched: Microsoft released a 'Fix it' solution.
  • 2013-01-14: patched: Official security bulletin MS13-008 released.
  • 2024-07-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats