PT-2012-1235 · Microsoft · Xml Core Services+2
Published
2012-06-13
·
Updated
2025-03-14
·
CVE-2012-1889
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft XML Core Services versions 3.0 through 6.0
Description
The issue allows remote attackers to execute arbitrary code or cause a denial of service due to memory corruption via a crafted web site. This is caused by the component accessing uninitialized memory locations. An attacker who successfully exploits this issue could take complete control of an affected system, then install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Recommendations
For Microsoft XML Core Services versions 3.0 through 6.0, update to a version that fixes the memory corruption issue to prevent remote code execution.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
RCE
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xml Core Services
Office
Sharepoint Server