CVE-2012-1858: Infoleak
The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1858?
CVE-2012-1858 has a severity rating of Important according to Microsoft's security bulletin.
How do I fix CVE-2012-1858?
To fix CVE-2012-1858, update affected Microsoft products such as Internet Explorer and Lync with the latest security patches.
Which versions of Internet Explorer are affected by CVE-2012-1858?
CVE-2012-1858 affects Internet Explorer 8 and 9.
Can CVE-2012-1858 lead to remote attacks?
Yes, CVE-2012-1858 can allow remote attackers to conduct cross-site scripting (XSS) attacks.
What systems are vulnerable to CVE-2012-1858?
Vulnerable systems include Microsoft Lync 2010, Internet Explorer 8, and Internet Explorer 9 on specific Windows operating systems.