Security Advisory

CVE-2012-1876

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-06-12 22:00:00
Last updated 2024-08-06 19:08:38
Assigner microsoft
CVSS score not scored
State PUBLISHED

Description

Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.