Sploitus

Exploit for Microsoft XML Core Services memory corruption

saint · 2012-06-27

Exploit Code

MARKDOWN33 lines
## https://sploitus.com/exploit?id=SAINT:46694E962B00AF2326A1EEB3134C6536
Added: 06/27/2012  
CVE: [CVE-2012-1889](<https://vulners.com/cve/CVE-2012-1889>)  
BID: [53934](<http://www.securityfocus.com/bid/53934>)  
OSVDB: [82873](<http://www.osvdb.org/82873>)  


### Background

[Microsoft XML Core Services](<http://msdn.microsoft.com/en-us/library/ms763742.aspx>) allows developers to create XML-based applications. 

### Problem

A memory corruption vulnerability allows command execution when a user opens a specially crafted web page, which causes MSXML to access an uninitialized object. 

### Resolution

See [Microsoft Security Advisory 2719615](<http://technet.microsoft.com/en-us/security/advisory/2719615>) for fix information and workarounds. 

### References

<http://technet.microsoft.com/en-us/security/advisory/2719615>  


### Limitations

Exploit works on Windows XP and Windows 7 and requires a user to open the exploit page in Internet Explorer 8 or 9. 

JRE 6 must be installed on Windows 7 targets. 

### Platforms

Windows