ZeroHour

CVE-2012-4792

KEVmass

Use-After-Free RCE in Microsoft Internet Explorer (CISA KEV)

CISA: Microsoft Internet Explorer Use-After-Free Vulnerability

CVSS
EPSS
79%p100
Published
KEV added
AI analysis

Microsoft Internet Explorer contains a use-after-free vulnerability (CWE-416) in which an attacker can trigger access to an object that was either never properly allocated or has already been deleted, demonstrated in the flaw record by a CDwnBindInfo object. A remote attacker exploits it by enticing a user to a crafted web site, and successful exploitation yields arbitrary code execution in the context of the logged-on user. Potentially affected parties are users of Microsoft Internet Explorer, which CISA notes is an end-of-life product. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-23, carries a 78.7% EPSS probability of exploitation within 30 days (top percentile), and related reporting ('Miniduke: Web Based Infection Vector', 'Group 72') underscores web-based infection vectors for this class of IE flaw; no public PoC is known and ransomware use is unknown.

What to do: Per CISA's required action, the impacted product is end-of-life: retire or disconnect any systems still relying on Internet Explorer and move users to a supported browser such as Microsoft Edge. Audit legacy Windows hosts, kiosks, and line-of-business web apps that still invoke IE, and where a supported platform allows it apply Microsoft's cumulative Internet Explorer security update addressing this CVE (MS13-002). On any remaining legacy systems, restrict web browsing to trusted sites until the software is retired.

Affected
Microsoft Internet Explorer
Estimated exposure
masshundreds of millions of users historically (IE shipped as the default Windows browser); current still-vulnerable install base unknown — Internet Explorer was bundled with effectively every Windows desktop for years, making the historical exposure universe enormous, but the source data gives no version range or install counts, and with the product end-of-life the number of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Internet Explorer
Weakness
CWE-416

In the news