CVE-2012-1545
medium · 5.8Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
5.8
CVSS
20.1%
EPSS (exploit prob.)
97th
EPSS percentile
2012-03-09
Published
AV:N/AC:M/Au:N/C:N/I:P/A:P
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | ie | 10 |
| microsoft | internet_explorer | 6.0 |
| microsoft | internet_explorer | 6.00.2462.0000 |
| microsoft | internet_explorer | 6.00.2479.0006 |
| microsoft | internet_explorer | 6.0.2600 |
| microsoft | internet_explorer | 6.00.2600.0000 |
| microsoft | internet_explorer | 6.0.2800 |
| microsoft | internet_explorer | 6.0.2800.1106 |
| microsoft | internet_explorer | 6.00.2800.1106 |
| microsoft | internet_explorer | 6.0.2900 |
| microsoft | internet_explorer | 6.0.2900.2180 |
| microsoft | internet_explorer | 6.00.2900.2180 |
| microsoft | internet_explorer | 6.00.3663.0000 |
| microsoft | internet_explorer | 6.00.3718.0000 |
| microsoft | internet_explorer | 6.00.3790.0000 |
| microsoft | internet_explorer | 6.00.3790.1830 |
| microsoft | internet_explorer | 6.00.3790.3959 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0.5730 |
| microsoft | internet_explorer | 7.0.5730.11 |
| microsoft | internet_explorer | 7.00.5730.1100 |
| microsoft | internet_explorer | 7.00.6000.16386 |
| microsoft | internet_explorer | 7.00.6000.16441 |
| microsoft | internet_explorer | 8.0.6001 |
| microsoft | internet_explorer | 8.0.6001 |
| microsoft | internet_explorer | 9 |
Check a specific version with /api/v1/cve/match.
References
- http://arstechnica.com/business/news/2012/03/ie-9-on-latest-windows-gets-stomped-at-hacker-contest.ars
- http://pwn2own.zerodayinitiative.com/status.html
- http://twitter.com/vupen/statuses/177895844828291073
- http://www.zdnet.com/blog/security/pwn2own-2012-ie-9-hacked-with-two-0day-vulnerabilities/10621
- http://arstechnica.com/business/news/2012/03/ie-9-on-latest-windows-gets-stomped-at-hacker-contest.ars
- http://pwn2own.zerodayinitiative.com/status.html
- http://twitter.com/vupen/statuses/177895844828291073
- http://www.zdnet.com/blog/security/pwn2own-2012-ie-9-hacked-with-two-0day-vulnerabilities/10621
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-1545