← back
CVE-2012-1876

CVE-2012-1876

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 65%
from disclosure to weapon51 days
Published on NVDJun 12
1st PoC+51d
metasploitJun 12
exploitation probability
65%top 1% of all CVEs
observed exploitation
nono source reports it
7 public exploit(s)
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.