5.8

CVE-2012-1545

Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Ie Version 10 Update consumer_preview
Microsoft ≫ Internet Explorer Version 6.0
Microsoft ≫ Internet Explorer Version 6.00.2462.0000
Microsoft ≫ Internet Explorer Version 6.00.2479.0006
Microsoft ≫ Internet Explorer Version 6.0.2600
Microsoft ≫ Internet Explorer Version 6.00.2600.0000
Microsoft ≫ Internet Explorer Version 6.0.2800
Microsoft ≫ Internet Explorer Version 6.0.2800.1106
Microsoft ≫ Internet Explorer Version 6.00.2800.1106
Microsoft ≫ Internet Explorer Version 6.0.2900
Microsoft ≫ Internet Explorer Version 6.0.2900.2180
Microsoft ≫ Internet Explorer Version 6.00.2900.2180
Microsoft ≫ Internet Explorer Version 6.00.3663.0000
Microsoft ≫ Internet Explorer Version 6.00.3718.0000
Microsoft ≫ Internet Explorer Version 6.00.3790.0000
Microsoft ≫ Internet Explorer Version 6.00.3790.1830
Microsoft ≫ Internet Explorer Version 6.00.3790.3959
Microsoft ≫ Internet Explorer Version 7.0
Microsoft ≫ Internet Explorer Version 7.0 Update beta
Microsoft ≫ Internet Explorer Version 7.0 Update beta1
Microsoft ≫ Internet Explorer Version 7.0 Update beta2
Microsoft ≫ Internet Explorer Version 7.0 Update beta3
Microsoft ≫ Internet Explorer Version 7.0.5730 Update unknown Edition gold
Microsoft ≫ Internet Explorer Version 7.0.5730.11
Microsoft ≫ Internet Explorer Version 7.00.5730.1100
Microsoft ≫ Internet Explorer Version 7.00.6000.16386
Microsoft ≫ Internet Explorer Version 7.00.6000.16441
Microsoft ≫ Internet Explorer Version 8.0.6001
Microsoft ≫ Internet Explorer Version 8.0.6001 Update beta
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 20.09% 0.971
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:N/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://arstechnica.com/business/news/2012/03/ie-9-on-latest-windows-gets-stomped-at-hacker-contest.ars
http://pwn2own.zerodayinitiative.com/status.html
http://twitter.com/vupen/statuses/177895844828291073
http://www.zdnet.com/blog/security/pwn2own-2012-ie-9-hacked-with-two-0day-vulnerabilities/10621