CVE-2012-0155: Code Injection
Published Feb 14, 2012
·Updated
Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Remote Code Execution Vulnerability."
Affected Software
7 affected components
Microsoft Internet Explorer=9
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Vista=sp2
Remediation
Event History
Feb 14, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0155?
CVE-2012-0155 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2012-0155?
To fix CVE-2012-0155, users should apply the security updates provided by Microsoft for Internet Explorer 9.
3
What versions of Internet Explorer are affected by CVE-2012-0155?
CVE-2012-0155 specifically affects Microsoft Internet Explorer 9.
4
Can CVE-2012-0155 be exploited remotely?
Yes, CVE-2012-0155 can be exploited remotely by accessing a deleted object in memory.
5
What attack vectors are associated with CVE-2012-0155?
CVE-2012-0155 can be exploited through specially crafted web pages that trigger the vulnerability.