CVE-2012-1889
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft XML Core Services Memory Corruption Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 84% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-787
מוצרים מושפעים
microsoft: xml core services; microsoft: windows 7; microsoft: windows 8; microsoft: windows server 2003; microsoft: windows server 2008; microsoft: windows server 2012; microsoft: windows vista; microsoft: windows xp; microsoft: expression web; microsoft: groove; microsoft: groove server; microsoft: office; microsoft: office compatibility pack; microsoft: office word viewer; microsoft: sharepoint server
קישורים
- http://technet.microsoft.com/security/advisory/2719615 Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-… PatchVendor Advisory
- http://technet.microsoft.com/security/advisory/2719615 Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-… PatchVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA12-174A.html Third Party AdvisoryUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA12-192A.html Third Party AdvisoryUS Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval… Broken Link
- http://www.us-cert.gov/cas/techalerts/TA12-174A.html Third Party AdvisoryUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA12-192A.html Third Party AdvisoryUS Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval… Broken Link