CVE-2012-2521: Code Injection
Published Aug 15, 2012
·Updated
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Asynchronous NULL Object Access Remote Code Execution Vulnerability."
Affected Software
4 affected components
Microsoft Internet Explorer=6
Microsoft Internet Explorer=7
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Event History
Aug 15, 2012
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2521?
CVE-2012-2521 has a critical severity rating, as it allows for remote code execution.
2
How do I fix CVE-2012-2521?
To fix CVE-2012-2521, users should update Microsoft Internet Explorer to a version that is not affected by the vulnerability.
3
What versions of Internet Explorer are affected by CVE-2012-2521?
CVE-2012-2521 affects Internet Explorer versions 6, 7, 8, and 9.
4
What type of attack does CVE-2012-2521 enable?
CVE-2012-2521 enables remote attackers to execute arbitrary code on the affected system.
5
Is there a workaround for CVE-2012-2521 if I cannot update?
There are no reliable workarounds for CVE-2012-2521, so updating is strongly recommended.