Overview
Microsoft Internet Explorer versions 6, 7, 8, and 9 are susceptible to a use-after-free vulnerability (CWE-416) that may result in remote code execution.
Description
Microsoft Internet Explorer 6/7/8/9 contains a use-after-free vulnerability in the CMshtmlEd::Exec() function. An attacker may leverage this vulnerability to execute arbitrary code. This vulnerability is being actively exploited in the wild and a Metasploit module is publicly available. |
Impact
By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code. |
Solution
Apply an Update Run Windows Update to apply the patch for this vulnerability. MS12-063 contains patches for this and other vulnerabilities as well. |
Apply a Microsoft Fix It utility
Use a different web browser Until Microsoft has released a patch for this vulnerability, consider using a different web browser for viewing untrusted web sites. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9.7 | AV:N/AC:L/Au:N/C:C/I:C/A:P |
Temporal | 9.2 | E:H/RL:W/RC:C |
Environmental | 6.9 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://blogs.technet.com/b/msrc/archive/2012/09/17/microsoft-releases-security-advisory-2757760.aspx
- http://technet.microsoft.com/en-us/security/advisory/2757760
- http://cwe.mitre.org/data/definitions/416.html
- http://osvdb.org/85532
- http://eromang.zataz.com/2012/09/16/zero-day-season-is-really-not-over-yet/
- https://community.rapid7.com/community/metasploit/blog/2012/09/17/lets-start-the-week-with-a-new-internet-explorer-0-day-in-metasploit
- https://www.virustotal.com/file/70f6a2c2976248221c251d9965ff2313bc0ed0aebb098513d76de6d8396a7125/analysis/1347710461/
- https://www.virustotal.com/file/9d66323794d493a1deaab66e36d36a820d814ee4dd50d64cddf039c2a06463a5/analysis/1347710777/
- http://dev.metasploit.com/redmine/projects/framework/repository/revisions/48a46f3b9415091a0cc76bd857a6bf90284b9fcd/entry/modules/exploits/windows/browser/ie_execcommand_uaf.rb
- http://labs.alienvault.com/labs/index.php/2012/new-internet-explorer-zero-day-being-exploited-in-the-wild/
Acknowledgements
This vulnerability was discovered in the wild.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2012-4969 |
Date Public: | 2012-09-17 |
Date First Published: | 2012-09-17 |
Date Last Updated: | 2012-09-21 17:16 UTC |
Document Revision: | 32 |