CVE-2012-1523: Code Injection
Published Jun 12, 2012
·Updated
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Center Element Remote Code Execution Vulnerability."
Affected Software
51 affected components
All of the following
Microsoft Internet Explorer=6
Any of the following
Microsoft Windows 2003 Server=sp2
Microsoft Windows 2003 Server=sp2
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
All of the following
Microsoft Internet Explorer=7
Any of the following
Microsoft Windows 2003 Server=sp2
Microsoft Windows 2003 Server=sp2
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
All of the following
Microsoft Internet Explorer=8
Any of the following
Microsoft Windows 2003 Server=sp2
Microsoft Windows 7
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
Microsoft Internet Explorer=6
Microsoft Windows 2003 Server=sp2
Microsoft Windows 2003 Server=sp2
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
Microsoft Internet Explorer=7
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Internet Explorer=8
Microsoft Windows 7
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2
Event History
Jun 12, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1523?
CVE-2012-1523 is rated as critical due to its potential to allow remote code execution.
2
How do I fix CVE-2012-1523?
To fix CVE-2012-1523, ensure you update to the latest version of Internet Explorer provided by Microsoft.
3
What versions of Internet Explorer are affected by CVE-2012-1523?
CVE-2012-1523 affects Internet Explorer versions 6, 7, and 8.
4
What types of attacks can CVE-2012-1523 enable?
CVE-2012-1523 can enable remote attackers to execute arbitrary code on affected systems.
5
Is there a workaround for CVE-2012-1523?
The recommended workaround for CVE-2012-1523 is to disable Active Scripting in Internet Explorer until a fix is applied.