ZeroHour

CVE-2012-1889

KEVmass

Memory Corruption RCE in Microsoft XML Core Services

CISA: Microsoft XML Core Services Memory Corruption Vulnerability

CVSS
EPSS
84%p100
Published
KEV added
AI analysis

Microsoft XML Core Services (MSXML) contains a memory corruption flaw (CWE-119) that can allow remote code execution when the component processes attacker-crafted content, such as a malicious web page or XML document loaded through Internet Explorer. Successful exploitation lets an attacker run arbitrary code in the security context of the logged-on user, gaining the ability to install programs, and view, change, or delete data; an admin-context victim would yield full system compromise. Any Windows system shipping the affected MSXML components is affected, which at the time of disclosure meant essentially the entire Windows installed base. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-06-08, EPSS assigns it an 83.6% probability of exploitation in the next 30 days (top percentile), and related reporting ties it to observed in-the-wild and APT activity, though public ransomware association is listed as unknown. No public proof-of-concept is cataloged, but the KEV and EPSS signals indicate active, ongoing exploitation risk.

What to do: Apply the vendor updates for XML Core Services released in the July 2012 Patch Tuesday on all Windows systems, prioritizing internet-facing and legacy endpoints, per the CISA KEV required action. Because exploitation is triggered via crafted web/XML content, restrict or upgrade legacy Internet Explorer usage and block untrusted web content on affected hosts. Hunt for exploitation indicators given the 2022-06-08 KEV listing and high EPSS score, and verify MSXML-related patches are present in your patch inventory.

Affected
Microsoft XML Core Services (MSXML)
Estimated exposure
mass≈hundreds of millions of Windows endpoints (MSXML ships as a core Windows component) — MSXML is bundled system-wide with Windows and exploited via web content, so at disclosure nearly every Windows installation of the era was potentially exposed, an order of magnitude in the hundreds of millions of devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.

CISA Known Exploited Vulnerability
Affected
Microsoft XML Core Services
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
XML Core Services
Weakness
CWE-119

In the news