CVE-2012-0012: Medium severity Microsoft Internet Explorer vulnerability
Published Feb 14, 2012
·Updated
Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka "Null Byte Information Disclosure Vulnerability."
Affected Software
7 affected components
Microsoft Internet Explorer=9
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Vista=sp2
Remediation
Event History
Feb 14, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker needs to cause a user to visit a crafted web site. The vulnerability is remotely exploitable and does not require authentication.
2
What information could be exposed?
Successful exploitation can allow an attacker to read data from arbitrary locations in the affected process's memory. The provided impact information indicates confidentiality impact only, with no stated integrity or availability impact.
3
Is a fix available?
Yes. A patch is available for this vulnerability.