CVE-2012-1889
HIGH KEVMicrosoft Xml Core Services - Out-of-Bounds Write
Title source: ruleDescription
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/19186
metasploit
WORKING POC
GOOD
by inking26, binjo, sinn3r, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/msxml_get_definition_code_exec.rb
References (6)
Scores
CVSS v3
8.8
EPSS
0.9312
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-06-08
VulnCheck KEV
2012-09-01
InTheWild.io
2015-09-09
ENISA EUVD
EUVD-2012-1899
CWE
CWE-787
Status
published
Products (4)
microsoft/xml_core_services
3.0
microsoft/xml_core_services
4.0
microsoft/xml_core_services
6.0
microsoft/xml_core_services
5.0
Published
Jun 13, 2012
KEV Added
Jun 08, 2022
Tracked Since
Feb 18, 2026