CVE-2012-4792: Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object.
Other sources
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect Microsoft Internet Explorer 6 through 8 from the network if still in use.
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4792?
CVE-2012-4792 has a critical severity rating due to its potential to allow remote code execution.
How do I fix CVE-2012-4792?
To fix CVE-2012-4792, users should update Internet Explorer to the latest version available from Microsoft.
Which versions of Internet Explorer are affected by CVE-2012-4792?
CVE-2012-4792 affects Internet Explorer versions 6, 7, and 8 on supported Windows operating systems.
Can CVE-2012-4792 be exploited remotely?
Yes, CVE-2012-4792 can be exploited remotely through specially crafted web pages.
What are the potential consequences of CVE-2012-4792 exploitation?
Successful exploitation of CVE-2012-4792 could allow an attacker to execute arbitrary code, potentially compromising the system.