Summary
This host is missing a critical security update according to Microsoft Bulletin MS13-008.
Impact
Successful exploitation could will remote attackers to gain sensitive information or execute arbitrary code in the context of the current user.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms13-008
Insight
Flaw exists due to the way that Internet Explorer accesses an object that has been deleted or has not been properly allocated and causing use-after-free error when handling the CDwnBindInfo object.
Affected
Microsoft Internet Explorer version 6.x/7.x/8.x
References
- http://secunia.com/advisories/51695
- http://securitytracker.com/id?1027930
- http://support.microsoft.com/kb/2794220
- http://technet.microsoft.com/en-us/security/advisory/2794220
- http://www.kb.cert.org/vuls/id/154201
- http://www.osvdb.org/88774
- http://xforce.iss.net/xforce/xfdb/80885
- https://technet.microsoft.com/en-au/security/bulletin/ms13-008
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2012-4792 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft Internet Explorer mshtml.dll Remote Memory Corruption Vulnerability (942615)
- Microsoft Internet Explorer Multiple Memory Corruption Vulnerabilities (2870699)
- Cumulative Security Update for Internet Explorer (972260)
- Microsoft IIS Security Bypass Vulnerability (970483)
- ISA Server 2000 and Proxy Server 2.0 Internet Content Spoofing (888258)