CVE-2012-1876
HIGH 9.3EPSS 65.0%
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
- CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 64.96% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2012-06-12
- Updated
- 2024-08-06
Proof-of-concept exploits (3)
- ExploitCN/CVE-2012-1876-win7_x86_and_win7x640★ · 2022-02-08
- WizardVan/CVE-2012-18760★ · 2015-05-03
- migraine-sudo/Arsenal2★ · 2019-12-20
Metasploit modules (1)
ExploitDB entries (5)
- https://www.exploit-db.com/exploits/35273
- https://www.exploit-db.com/exploits/34815
- https://www.exploit-db.com/exploits/33944
- https://www.exploit-db.com/exploits/24017
- https://www.exploit-db.com/exploits/20174