Executive brief
A use-after-free vulnerability exists in the CMshtmlEd::Exec function in mshtml.dll within Microsoft Internet Explorer 6 through 9. Remote attackers can exploit this flaw to execute arbitrary code via a specially crafted website.
Affected products
- Microsoft Internet Explorer 6 through 9
Timeline
- 2012-09-17: disclosed: Publicly reported as a zero-day vulnerability.
- 2012-09-01: exploited: Exploited in the wild in September 2012.
- 2022-06-08: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.