CVE-2012-1889
KEVmassMemory Corruption RCE in Microsoft XML Core Services
CISA: Microsoft XML Core Services Memory Corruption Vulnerability
Microsoft XML Core Services (MSXML) contains a memory corruption flaw (CWE-119) that can allow remote code execution when the component processes attacker-crafted content, such as a malicious web page or XML document loaded through Internet Explorer. Successful exploitation lets an attacker run arbitrary code in the security context of the logged-on user, gaining the ability to install programs, and view, change, or delete data; an admin-context victim would yield full system compromise. Any Windows system shipping the affected MSXML components is affected, which at the time of disclosure meant essentially the entire Windows installed base. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-06-08, EPSS assigns it an 83.6% probability of exploitation in the next 30 days (top percentile), and related reporting ties it to observed in-the-wild and APT activity, though public ransomware association is listed as unknown. No public proof-of-concept is cataloged, but the KEV and EPSS signals indicate active, ongoing exploitation risk.
What to do: Apply the vendor updates for XML Core Services released in the July 2012 Patch Tuesday on all Windows systems, prioritizing internet-facing and legacy endpoints, per the CISA KEV required action. Because exploitation is triggered via crafted web/XML content, restrict or upgrade legacy Internet Explorer usage and block untrusted web content on affected hosts. Hunt for exploitation indicators given the 2022-06-08 KEV listing and high EPSS score, and verify MSXML-related patches are present in your patch inventory.
| Microsoft XML Core Services (MSXML) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.
- Affected
- Microsoft XML Core Services
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- XML Core Services
- Weakness
- CWE-119