2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2012-4792" ,
"sourceIdentifier" : "secure@microsoft.com" ,
"published" : "2012-12-30T18:55:01.477" ,
2024-12-19 21:03:43 +00:00
"lastModified" : "2024-12-19T19:49:43.483" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012."
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad de uso despu\u00e9s de liberaci\u00f3n en Microsoft Internet Explorer v6 a v8 permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de un sitio web dise\u00f1ado para tal fin que desencadena el acceso a un objeto que (1) no se asign\u00f3 correctamente o (2) se elimina, tal y como se demuestra con un objeto CDwnBindInfo y es explotado en Diciembre de 2012.\r\n"
}
] ,
"metrics" : {
2024-08-01 14:03:18 +00:00
"cvssMetricV31" : [
2024-08-14 16:03:15 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH" ,
2024-08-14 16:03:15 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-08-14 16:03:15 +00:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
} ,
2024-08-01 14:03:18 +00:00
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH" ,
2024-08-01 14:03:18 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-08-01 14:03:18 +00:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
}
] ,
2023-04-24 12:24:31 +02:00
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 9.3 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "COMPLETE" ,
"integrityImpact" : "COMPLETE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "COMPLETE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 10.0 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
2024-12-08 03:06:42 +00:00
"cisaExploitAdd" : "2024-07-23" ,
"cisaActionDue" : "2024-08-13" ,
"cisaRequiredAction" : "The impacted product is end-of-life and should be disconnected if still in use." ,
"cisaVulnerabilityName" : "Microsoft Internet Explorer Use-After-Free Vulnerability" ,
2023-04-24 12:24:31 +02:00
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
2024-08-14 16:03:15 +00:00
"value" : "CWE-416"
2023-04-24 12:24:31 +02:00
}
]
2024-08-01 14:03:18 +00:00
} ,
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-416"
}
]
2023-04-24 12:24:31 +02:00
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "693D3C1C-E3E4-49DB-9A13-44ADDFF82507"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "4D3B5E4F-56A6-4696-BBB4-19DF3613D020"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE477A73-4EE4-41E9-8694-5A3D5DC88656"
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:x64:*" ,
"matchCriteriaId" : "BADB0479-3E0E-4326-B568-9DBDCACF0B5E"
2023-04-24 12:24:31 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1A33FA7F-BB2A-4C66-B608-72997A2BD1DB"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "4D3B5E4F-56A6-4696-BBB4-19DF3613D020"
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*" ,
"matchCriteriaId" : "F8216946-5F76-48B9-91CC-207F657D7D3C"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x86:*" ,
"matchCriteriaId" : "B36BFDA7-596B-45EA-AACE-F8A796CECDBB"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:itanium:*" ,
"matchCriteriaId" : "FFFD8C6B-7A46-484C-8701-81D58AB1C2CF"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
2023-12-07 19:00:41 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "0A0D2704-C058-420B-B368-372D1129E914"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "BF1AD1A1-EE20-4BCE-9EE6-84B27139811C"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE477A73-4EE4-41E9-8694-5A3D5DC88656"
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:x64:*" ,
"matchCriteriaId" : "BADB0479-3E0E-4326-B568-9DBDCACF0B5E"
2023-04-24 12:24:31 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A52E757F-9B41-43B4-9D67-3FEDACA71283"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E33796DB-4523-4F04-B564-ADF030553D51"
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x64:*" ,
"matchCriteriaId" : "7FE8B00B-4F39-4755-A323-8AD71F5E3EBE"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x86:*" ,
"matchCriteriaId" : "06BBFA69-94E2-4BAB-AFD3-BC434B11D106"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "4D3B5E4F-56A6-4696-BBB4-19DF3613D020"
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_server_2008:*:r2:*:*:*:*:itanium:*" ,
"matchCriteriaId" : "C6012A8B-D154-42F1-BE7A-828D344487FB"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_server_2008:*:r2:*:*:*:*:x64:*" ,
"matchCriteriaId" : "E33988B9-543E-4340-AD84-FE23250F2D98"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*" ,
"matchCriteriaId" : "2127D10C-B6F3-4C1D-B9AA-5D78513CC996"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*" ,
"matchCriteriaId" : "AB425562-C0A0-452E-AABE-F70522F15E1A"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
2023-12-07 19:00:41 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "0A0D2704-C058-420B-B368-372D1129E914"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "BF1AD1A1-EE20-4BCE-9EE6-84B27139811C"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE477A73-4EE4-41E9-8694-5A3D5DC88656"
} ,
{
"vulnerable" : false ,
2024-08-14 16:03:15 +00:00
"criteria" : "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:x64:*" ,
"matchCriteriaId" : "C6109348-BC79-4ED3-8D41-EA546A540C79"
2023-04-24 12:24:31 +02:00
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://blog.fireeye.com/research/2012/12/council-foreign-relations-water-hole-attack-details.html" ,
2024-08-14 16:03:15 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Broken Link"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "http://blogs.technet.com/b/srd/archive/2012/12/29/new-vulnerability-affecting-internet-explorer-8-users.aspx" ,
2024-08-14 16:03:15 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Broken Link"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "http://blogs.technet.com/b/srd/archive/2012/12/31/microsoft-quot-fix-it-quot-available-for-internet-explorer-6-7-and-8.aspx" ,
2024-08-14 16:03:15 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Broken Link"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "http://eromang.zataz.com/2012/12/29/attack-and-ie-0day-informations-used-against-council-on-foreign-relations/" ,
2024-08-14 16:03:15 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Third Party Advisory"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "http://labs.alienvault.com/labs/index.php/2012/just-another-water-hole-campaign-using-an-internet-explorer-0day/" ,
2024-08-14 16:03:15 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Broken Link"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "http://packetstormsecurity.com/files/119168/Microsoft-Internet-Explorer-CDwnBindInfo-Object-Use-After-Free.html" ,
2024-08-14 16:03:15 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "http://technet.microsoft.com/security/advisory/2794220" ,
"source" : "secure@microsoft.com" ,
"tags" : [
2024-08-14 16:03:15 +00:00
"Patch" ,
2023-04-24 12:24:31 +02:00
"Vendor Advisory"
]
} ,
{
"url" : "http://www.kb.cert.org/vuls/id/154201" ,
"source" : "secure@microsoft.com" ,
"tags" : [
2024-08-14 16:03:15 +00:00
"Third Party Advisory" ,
2023-04-24 12:24:31 +02:00
"US Government Resource"
]
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA13-008A.html" ,
"source" : "secure@microsoft.com" ,
"tags" : [
2024-08-14 16:03:15 +00:00
"Third Party Advisory" ,
2023-04-24 12:24:31 +02:00
"US Government Resource"
]
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA13-015A.html" ,
"source" : "secure@microsoft.com" ,
"tags" : [
2024-08-14 16:03:15 +00:00
"Third Party Advisory" ,
2023-04-24 12:24:31 +02:00
"US Government Resource"
]
} ,
{
"url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-008" ,
2024-08-14 16:03:15 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ie_cbutton_uaf.rb" ,
2024-08-14 16:03:15 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Third Party Advisory"
]
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16361" ,
2024-08-14 16:03:15 +00:00
"source" : "secure@microsoft.com" ,
"tags" : [
"Broken Link"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://blog.fireeye.com/research/2012/12/council-foreign-relations-water-hole-attack-details.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Broken Link"
]
} ,
{
"url" : "http://blogs.technet.com/b/srd/archive/2012/12/29/new-vulnerability-affecting-internet-explorer-8-users.aspx" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Broken Link"
]
} ,
{
"url" : "http://blogs.technet.com/b/srd/archive/2012/12/31/microsoft-quot-fix-it-quot-available-for-internet-explorer-6-7-and-8.aspx" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Broken Link"
]
} ,
{
"url" : "http://eromang.zataz.com/2012/12/29/attack-and-ie-0day-informations-used-against-council-on-foreign-relations/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://labs.alienvault.com/labs/index.php/2012/just-another-water-hole-campaign-using-an-internet-explorer-0day/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Broken Link"
]
} ,
{
"url" : "http://packetstormsecurity.com/files/119168/Microsoft-Internet-Explorer-CDwnBindInfo-Object-Use-After-Free.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://technet.microsoft.com/security/advisory/2794220" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://www.kb.cert.org/vuls/id/154201" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA13-008A.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA13-015A.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
} ,
{
"url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-008" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ie_cbutton_uaf.rb" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16361" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Broken Link"
]
2023-04-24 12:24:31 +02:00
}
]
}