CVE-2012-0171: Code Injection
Published Apr 10, 2012
·Updated
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "SelectAll Remote Code Execution Vulnerability."
Affected Software
13 affected components
Microsoft Internet Explorer=6
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
Microsoft Internet Explorer=7
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Internet Explorer=8
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2-sp1
Microsoft Internet Explorer=9
Remediation
Event History
Apr 10, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0171?
CVE-2012-0171 has a critical severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2012-0171?
To fix CVE-2012-0171, you should apply the relevant security update provided by Microsoft.
3
Which versions of Internet Explorer are affected by CVE-2012-0171?
CVE-2012-0171 affects Internet Explorer versions 6, 7, 8, and 9.
4
Can CVE-2012-0171 be exploited remotely?
Yes, CVE-2012-0171 can be exploited remotely by attackers through malicious web pages.
5
What symptoms indicate an exploitation of CVE-2012-0171?
Symptoms of exploitation may include abnormal behavior of the application, system crashes, or unexpected web browser activity.