CVE-2012-2557: Use After Free
Published Sep 21, 2012
·Updated
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "cloneNode Use After Free Vulnerability."
Affected Software
15 affected components
Microsoft Internet Explorer=6
Microsoft Internet Explorer=6-beta1
Microsoft Internet Explorer=6-sp1
Microsoft Internet Explorer=6-sp2
Microsoft Internet Explorer=6-sp3
Microsoft Internet Explorer=7
Microsoft Internet Explorer=7-beta1
Microsoft Internet Explorer=7-beta2
Microsoft Internet Explorer=7-beta3
Microsoft Internet Explorer=7-rc1
Microsoft Internet Explorer=8
Microsoft Internet Explorer=8-beta1
Microsoft Internet Explorer=8-beta2
Microsoft Internet Explorer=8-rc1
Microsoft Internet Explorer=9
Event History
Sep 21, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2557?
CVE-2012-2557 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2012-2557?
To fix CVE-2012-2557, users should apply the latest security updates provided by Microsoft for Internet Explorer.
3
What versions of Internet Explorer are affected by CVE-2012-2557?
CVE-2012-2557 affects Internet Explorer versions 6, 7, and 8.
4
What type of vulnerability is CVE-2012-2557?
CVE-2012-2557 is a use-after-free vulnerability that can allow an attacker to execute arbitrary code.
5
How can attackers exploit CVE-2012-2557?
Attackers can exploit CVE-2012-2557 by crafting malicious websites that trigger the vulnerability when visited.