Junglewise Threat Intelligence

CVE-2012-4969: Microsoft Internet Explorer Use-After-Free Vulnerability

CVE-2012-4969 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2022-06-08

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability exists in the CMshtmlEd::Exec function in mshtml.dll within Microsoft Internet Explorer 6 through 9. Remote attackers can exploit this flaw to execute arbitrary code via a specially crafted website.

Affected products

  • Microsoft Internet Explorer 6 through 9

Timeline

  • 2012-09-17: disclosed: Publicly reported as a zero-day vulnerability.
  • 2012-09-01: exploited: Exploited in the wild in September 2012.
  • 2022-06-08: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats