CVE-2012-1889

HIGH KEV

Microsoft Xml Core Services - Out-of-Bounds Write

Title source: rule

Description

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/19186
nomisec WORKING POC 4 stars
by whu-enjoy · client-side
https://github.com/whu-enjoy/CVE-2012-1889
nomisec WORKING POC 1 stars
by l-iberty · poc
https://github.com/l-iberty/cve-2012-1889
metasploit WORKING POC GOOD
by inking26, binjo, sinn3r, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/msxml_get_definition_code_exec.rb

Scores

CVSS v3 8.8
EPSS 0.9312
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-06-08
VulnCheck KEV 2012-09-01
InTheWild.io 2015-09-09
ENISA EUVD EUVD-2012-1899
CWE
CWE-787
Status published
Products (4)
microsoft/xml_core_services 3.0
microsoft/xml_core_services 4.0
microsoft/xml_core_services 6.0
microsoft/xml_core_services 5.0
Published Jun 13, 2012
KEV Added Jun 08, 2022
Tracked Since Feb 18, 2026