CVE Tools

CVE-2012-4792

Exploited in the wild. In CISA KEV since 2024‑07‑23. A vendor fix is available.

Published Updated Sources: CVE.org, NVD, BDU

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Identify whether any of your systems are running Microsoft Internet Explorer 6, 7, or 8 (including on Windows XP/Server 2003-era systems).
  2. If you still use those old Internet Explorer versions, stop using them for web browsing immediately and move users to a supported browser.
  3. For any impacted end-of-life Windows systems, disconnect them from the network (and especially from the internet) until patched/replaced.
  4. Apply the vendor security update guidance for CVE-2012-4792 / MS13-008 if your specific Windows version is eligible; otherwise, prioritize upgrade or replacement.
  5. Monitor for suspicious web-driven activity (unexpected new software, browser crashes, unknown processes) on machines that were used to visit websites.

What it is

From the CVE record

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.

In plain language

Written by AI from the record

CVE-2012-4792 is a serious flaw in Internet Explorer 6 through 8 that lets attackers run code on your computer after you visit a malicious website; if you’re still using these old browsers, you should treat it as a real threat and act now.

CVE-2012-4792 is a use-after-free remote code execution vulnerability in Microsoft Internet Explorer 6 through 8, triggered when a user visits a specially crafted web site; it does not require the attacker to have login access, and it has been confirmed in the CISA KEV program.

If you're affected

  • Full takeover of the workstation
  • Malware installed via web browsing
  • Ransomware risk from infected PCs
  • Business disruption from compromised machines

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS99th
Public exploit
CISA KEV
CISA KEV

Listed as exploited in the wild since 2024-07-23.

US federal agencies must remediate by 2024-08-13.

The impacted product is end-of-life and should be disconnected if still in use.
Public exploits

4 sources with a proof of concept or module.

Exploit links, PoCs and Metasploit modules after sign-in
EPSS

79% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

A public exploit existed 47 days before the patch.

  1. OpenVAS check added
  2. EPSS band changecritical → high
  3. Patch availablerecord updated
  4. Public exploit / PoCsource: github-poc
  5. Added to CISA KEV
  6. Publishedweakness classified, att&ck mapped

Affected products

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Scored 8.8 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction RequiredA user must click a link, open a file, or perform some action

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Microsoft Corp, not every advisory. This one: actively exploited.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store