9.3

CVE-2012-4787

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly initialized or (2) is deleted, aka "Improper Ref Counting Use After Free Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 9
   Microsoft ≫ Windows 7 Edition x64
   Microsoft ≫ Windows 7 Edition x86
   Microsoft ≫ Windows 7 Update sp1 Edition x64
   Microsoft ≫ Windows 7 Update sp1 Edition x86
   Microsoft ≫ Windows Server 2008 Update r2 Edition x64
   Microsoft ≫ Windows Server 2008 Update sp2 Edition x64
   Microsoft ≫ Windows Server 2008 Update sp2 Edition x86
   Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Internet Explorer Version 10
   Microsoft ≫ Windows 8 Version - Update - Edition x64
   Microsoft ≫ Windows 8 Version - Update - Edition x86
   Microsoft ≫ Windows Rt Version -
   Microsoft ≫ Windows Server 2012 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 17.57% 0.968
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CISA-ADP 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

http://www.us-cert.gov/cas/techalerts/TA12-346A.html
US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-077
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16211