CVE-2012-4969
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
- Affected products
- Internet Explorer
- Microsoft Internet Explorer
- = 6
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 81.7% (100th percentile)
- Weakness
- CWE-416
- NVD status
- Analyzed
- Published
- 2012-09-18
CVE-2012-4969 at NVD
8 known exploits for CVE-2012-4969
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft Internet Explorer - execCommand Use-After-Free (MS12-063) (Metasploit)
MS12-063 Microsoft Internet Explorer execCommand Use-After-Free Vulnerability
Internet Explorer CMshtmlEd execCommand Use After Free
Internet Explorer CMshtmlEd execCommand Use After Free
Internet Explorer CMshtmlEd execCommand Use After Free
Internet Explorer CMshtmlEd execCommand Use After Free
Immunity Canvas: IE_EXECCOMMAND
MS12-063 Microsoft Internet Explorer execCommand Use-After-Free Vulnerability