CVE-2012-4792
Exploited in the wild. In CISA KEV since 2024‑07‑23. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Identify whether any of your systems are running Microsoft Internet Explorer 6, 7, or 8 (including on Windows XP/Server 2003-era systems).
- If you still use those old Internet Explorer versions, stop using them for web browsing immediately and move users to a supported browser.
- For any impacted end-of-life Windows systems, disconnect them from the network (and especially from the internet) until patched/replaced.
- Apply the vendor security update guidance for CVE-2012-4792 / MS13-008 if your specific Windows version is eligible; otherwise, prioritize upgrade or replacement.
- Monitor for suspicious web-driven activity (unexpected new software, browser crashes, unknown processes) on machines that were used to visit websites.
What it is
From the CVE record
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
In plain language
Written by AI from the recordCVE-2012-4792 is a serious flaw in Internet Explorer 6 through 8 that lets attackers run code on your computer after you visit a malicious website; if you’re still using these old browsers, you should treat it as a real threat and act now.
CVE-2012-4792 is a use-after-free remote code execution vulnerability in Microsoft Internet Explorer 6 through 8, triggered when a user visits a specially crafted web site; it does not require the attacker to have login access, and it has been confirmed in the CISA KEV program.
If you're affected
- Full takeover of the workstation
- Malware installed via web browsing
- Ransomware risk from infected PCs
- Business disruption from compromised machines
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2024-07-23.
US federal agencies must remediate by 2024-08-13.
The impacted product is end-of-life and should be disconnected if still in use.
- Public exploits
4 sources with a proof of concept or module.
Exploit links, PoCs and Metasploit modules after sign-in- EPSS
79% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
A public exploit existed 47 days before the patch.
- OpenVAS check added
- EPSS band changecritical → high
- Patch availablerecord updated
- Public exploit / PoCsource: github-poc
- Added to CISA KEV
- Publishedweakness classified, att&ck mapped
Affected products
- Windows Server 2003 Service Pack 2Operating Systems / windows
- Windows VistaOperating Systems / windows
- Windows 7 Service Pack 1Operating Systems / windows
- Windows Server 2008 Service Pack 2Operating Systems / windows
- Windows XP Service Pack 3Operating Systems / windows
- Windows Server 2008 R2 Service Pack 1Operating Systems / windows
- Internet ExplorerConsumer Software / browser
- Windows XP Professional Edition Service Pack 2Operating Systems / windows
And 5 more affected products. See all after sign-in
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Scored 8.8 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction RequiredA user must click a link, open a file, or perform some action
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
- Initial AccessT1190Exploit Public-Facing Applicationhigh confidence
- Privilege EscalationT1068Exploitation for Privilege Escalationhigh confidence
Sources
References in the record
- learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2013/2794220?redirectedfrom=MSDN&
- learn.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-008&
- github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ie_cbutton_uaf.rb&
And 20 more references. See all after sign-in
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Microsoft Corp, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI