CVE-2012-1874: Code Injection
Published Jun 12, 2012
·Updated
Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows user-assisted remote attackers to execute arbitrary code by accessing a deleted object, aka "Developer Toolbar Remote Code Execution Vulnerability."
Affected Software
35 affected components
All of the following
Any of the following
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Any of the following
Microsoft Windows 7
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Microsoft Windows 7
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
Event History
Jun 12, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1874?
CVE-2012-1874 has a severity rating of Critical due to its ability to allow remote code execution.
2
How do I fix CVE-2012-1874?
To fix CVE-2012-1874, update Internet Explorer to the latest version provided by Microsoft.
3
Which versions of Internet Explorer are affected by CVE-2012-1874?
CVE-2012-1874 specifically affects Microsoft Internet Explorer versions 8 and 9.
4
What type of vulnerability is represented by CVE-2012-1874?
CVE-2012-1874 is a remote code execution vulnerability caused by improper handling of objects in memory.
5
Can CVE-2012-1874 be exploited remotely?
Yes, CVE-2012-1874 can be exploited remotely if a user is persuaded to visit a malicious website.