CVE-2012-1875

EXPLOITED

Microsoft Internet Explorer - Code Injection

Title source: rule

Description

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability."

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/19141
metasploit WORKING POC NORMAL
by Dark Son, Unknown, Yichong Lin, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms12_037_same_id.rb

Scores

EPSS 0.8218
EPSS Percentile 99.2%

Details

VulnCheck KEV 2012-09-01
CWE
CWE-94
Status published
Products (1)
microsoft/internet_explorer 8
Published Jun 12, 2012
Tracked Since Feb 18, 2026