CVE-2012-1545
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
5.8
Description
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| microsoft | ie | 10 | |
| microsoft | internet_explorer | 6.0 | |
| microsoft | internet_explorer | 6.00.2462.0000 | |
| microsoft | internet_explorer | 6.00.2479.0006 | |
| microsoft | internet_explorer | 6.0.2600 | |
| microsoft | internet_explorer | 6.00.2600.0000 | |
| microsoft | internet_explorer | 6.0.2800 | |
| microsoft | internet_explorer | 6.0.2800.1106 | |
| microsoft | internet_explorer | 6.00.2800.1106 | |
| microsoft | internet_explorer | 6.0.2900 | |
| microsoft | internet_explorer | 6.0.2900.2180 | |
| microsoft | internet_explorer | 6.00.2900.2180 | |
| microsoft | internet_explorer | 6.00.3663.0000 | |
| microsoft | internet_explorer | 6.00.3718.0000 | |
| microsoft | internet_explorer | 6.00.3790.0000 | |
| microsoft | internet_explorer | 6.00.3790.1830 | |
| microsoft | internet_explorer | 6.00.3790.3959 | |
| microsoft | internet_explorer | 7.0 | |
| microsoft | internet_explorer | 7.0.5730 | |
| microsoft | internet_explorer | 7.0.5730.11 | |
| microsoft | internet_explorer | 7.00.5730.1100 | |
| microsoft | internet_explorer | 7.00.6000.16386 | |
| microsoft | internet_explorer | 7.00.6000.16441 | |
| microsoft | internet_explorer | 8.0.6001 | |
| microsoft | internet_explorer | 9 | |
References
- http://arstechnica.com/business/news/2012/03/ie-9-on-latest-windows-gets-stomped-at-hacker-contest.ars
- http://pwn2own.zerodayinitiative.com/status.html
- http://twitter.com/vupen/statuses/177895844828291073
- http://www.zdnet.com/blog/security/pwn2own-2012-ie-9-hacked-with-two-0day-vulnerabilities/10621
- http://arstechnica.com/business/news/2012/03/ie-9-on-latest-windows-gets-stomped-at-hacker-contest.ars
- http://pwn2own.zerodayinitiative.com/status.html
- http://twitter.com/vupen/statuses/177895844828291073
- http://www.zdnet.com/blog/security/pwn2own-2012-ie-9-hacked-with-two-0day-vulnerabilities/10621
CWEs
CWE-119
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.