5.8
CVE-2012-1545
- EPSS 20.09%
- Veröffentlicht 09.03.2012 11:55:01
- Zuletzt bearbeitet 16.06.2026 23:39:43
- Erkennungen
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 6.0
Microsoft ≫ Internet Explorer Version 6.00.2462.0000
Microsoft ≫ Internet Explorer Version 6.00.2479.0006
Microsoft ≫ Internet Explorer Version 6.0.2600
Microsoft ≫ Internet Explorer Version 6.00.2600.0000
Microsoft ≫ Internet Explorer Version 6.0.2800
Microsoft ≫ Internet Explorer Version 6.0.2800.1106
Microsoft ≫ Internet Explorer Version 6.00.2800.1106
Microsoft ≫ Internet Explorer Version 6.0.2900
Microsoft ≫ Internet Explorer Version 6.0.2900.2180
Microsoft ≫ Internet Explorer Version 6.00.2900.2180
Microsoft ≫ Internet Explorer Version 6.00.3663.0000
Microsoft ≫ Internet Explorer Version 6.00.3718.0000
Microsoft ≫ Internet Explorer Version 6.00.3790.0000
Microsoft ≫ Internet Explorer Version 6.00.3790.1830
Microsoft ≫ Internet Explorer Version 6.00.3790.3959
Microsoft ≫ Internet Explorer Version 7.0
Microsoft ≫ Internet Explorer Version 7.0 Update beta
Microsoft ≫ Internet Explorer Version 7.0 Update beta1
Microsoft ≫ Internet Explorer Version 7.0 Update beta2
Microsoft ≫ Internet Explorer Version 7.0 Update beta3
Microsoft ≫ Internet Explorer Version 7.0.5730 Update unknown Edition gold
Microsoft ≫ Internet Explorer Version 7.0.5730.11
Microsoft ≫ Internet Explorer Version 7.00.5730.1100
Microsoft ≫ Internet Explorer Version 7.00.6000.16386
Microsoft ≫ Internet Explorer Version 7.00.6000.16441
Microsoft ≫ Internet Explorer Version 8.0.6001
Microsoft ≫ Internet Explorer Version 8.0.6001 Update beta
Microsoft ≫ Internet Explorer Version 9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 20.09% | 0.971 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://arstechnica.com/business/news/2012/03/ie-9-on-latest-windows-gets-stomped-at-hacker-contest.ars
http://pwn2own.zerodayinitiative.com/status.html
http://twitter.com/vupen/statuses/177895844828291073
http://www.zdnet.com/blog/security/pwn2own-2012-ie-9-hacked-with-two-0day-vulnerabilities/10621