Skip to content
COOEY

EXPOSURES › CVE-2012-4792

CVE-2012-4792

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-07-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2012-4792 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 rceexploited-in-wildunpatched

Microsoft Internet Explorer's use-after-free vulnerability (CVE-2012-4792) allows remote attackers to execute arbitrary code via a crafted website.

This use-after-free flaw enables remote code execution through a crafted web page, exploiting a deleted CDwnBindInfo object in Internet Explorer. DIB organizations must immediately remove IE from production environments as it is end-of-life and unsupported, with a history of critical vulnerabilities that pose severe compliance risks under FedRAMP and NIST 800-171.

Shame score — While the vulnerability is critical and actively exploited, the product is end-of-life and the flaw is not zero-day, resulting in moderate embarrassment rather than high.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized