← לוח פגיעויות

CVE-2012-1889

גבוהה 8.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Microsoft XML Core Services Memory Corruption Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

מדדים

CVSS 3.1
8.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
84% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-787

מוצרים מושפעים

microsoft: xml core services; microsoft: windows 7; microsoft: windows 8; microsoft: windows server 2003; microsoft: windows server 2008; microsoft: windows server 2012; microsoft: windows vista; microsoft: windows xp; microsoft: expression web; microsoft: groove; microsoft: groove server; microsoft: office; microsoft: office compatibility pack; microsoft: office word viewer; microsoft: sharepoint server

קישורים