CVE-2012-0170: Code Injection
Published Apr 10, 2012
·Updated
Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnReadyStateChange Remote Code Execution Vulnerability."
Affected Software
2 affected components
Microsoft Internet Explorer=6
Microsoft Internet Explorer=7
Event History
Apr 10, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0170?
CVE-2012-0170 has a critical severity level due to its potential to allow remote code execution.
2
How do I fix CVE-2012-0170?
To fix CVE-2012-0170, users should upgrade to a newer version of Internet Explorer that is no longer affected.
3
What versions of Internet Explorer are affected by CVE-2012-0170?
CVE-2012-0170 affects Internet Explorer versions 6 and 7.
4
What type of vulnerability is CVE-2012-0170 classified as?
CVE-2012-0170 is classified as a remote code execution vulnerability.
5
What could happen if CVE-2012-0170 is exploited?
If CVE-2012-0170 is exploited, attackers can execute arbitrary code on the victim's system.