Skip to main content

CVE detail

CVE-2012-1889

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

CVSS 8.8 · HighBuzz score 69.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 69.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
24 evidence mentions in the snapshot
Diversity score
14.5
5 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
24 source links · newest first
  • The 5th installment in a series of posts tracking web-based threats over time from our Email Link Analysis (ELINK) system., specifically, statistics pertaining to malicious URLs, domains, exploit kits, vulnerabilities, and phishing scams.

    vendorunit42.paloaltonetworks.comNov 1, 2019, 1:00 PM
  • Our Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.

    vendorunit42.paloaltonetworks.comDec 27, 2018, 2:00 PM
  • Japanese commercial and critical infrastructure organizations have been targeted a long-running campaign dubbed Operation Dust Storm. Security firm Cylance have uncovered a long-running hacking campaign dubbed ‘Operation Dust Storm’ targeting commercial and critical infrastructure organizations in Japan. Threat actors behind the Operation Dust Storm have been active since at least 2010, the hackers targeted several organizations in Japan, […]

    newssecurityaffairs.comFeb 24, 2016, 7:07 AM
  • Commercial and critical infrastructure organizations in Japan have been targeted in a multi-year campaign dubbed by researchers “Operation Dust Storm.”

    newswww.securityweek.comFeb 23, 2016, 6:43 PM
  • Researchers at Symantec say the Elderwood attack platform is at the center of numerous zero-day attacks launched by hacker crews around the world this year.

    newswww.securityweek.comMay 15, 2014, 5:46 PM
  • The simplicity of the malware that paralyzed the computer networks of three banks and two broadcasters in technically sophisticated South Korea is a warning that U.S. corporations need to rethink security. The cybercriminals did nothing out of the ordinary in penetrating the organizations’ defenses on Wednesday. They used existing malware called “DarkSeoul,” changed its signature […]

    newswww.csoonline.comMar 22, 2013, 3:00 PM
  • Researchers at AlienVault shed some light on the evolution of the Sykipot malware attacks. The Sykipot attacks have exploited a number of zero-days during the past few years, including vulnerabilities affecting Adobe Reader, Adobe Flash Player and Microsoft Internet Explorer.

    newswww.securityweek.comMar 21, 2013, 6:54 PM
  • U.S companies and government agencies can learn from the large-scale disruptions that have simultaneously hit several banks and media outlets in South Korea in the last 24 hours. Early analyses by security firms suggest that the attacks were carried out using previously known vulnerabilities and exploits. So while considerable attention is being paid to whether […]

    newswww.csoonline.comMar 20, 2013, 3:00 PM
  • Where 2012 was a period of great innovation amongst cybercriminals and hackers – many of whom keenly develop new and hybridized attack vectors that build on a constantly expanding range of extensible code environments seen running on Windows and Apple Mac platforms – 2013 is likely to go down in the darkware IT history books as a period of consolidation. This trend will be driven, we predict, by the not inconsiderable fact that the incredible … More →

    newswww.helpnetsecurity.comJan 16, 2013, 2:00 PM
  • Researchers at Symantec say the waterholing attacks utilizing the recently-publicized Internet Explorer zero-day are tied to a gang responsible for a spate of similar kinds of attacks.

    newswww.securityweek.comJan 4, 2013, 2:29 PM
  • The latest Java vulnerability has been integrated into both Black Hole and Gong Da exploit kits, making it easier for cyber-criminals to launch attacks exploiting the flaw, a security researcher said.

    newswww.securityweek.comNov 22, 2012, 12:36 PM
  • An elite hacker group targeting defense industry sub-contractors has an inexhaustible supply of zero-days, or vulnerabilities that have yet to be publicized, much less patched, Symantec said today. In a blog post, the security firm said, “The group seemingly has an unlimited supply of zero-day vulnerabilities.” Symantec also laid out its analysis of the gang, […]

    newswww.csoonline.comSep 7, 2012, 3:00 PM
  • Here’s an overview of some of last week’s most interesting news, videos, interviews and articles: Worldwide IT spending to surpass $3.6 trillion in 2012 In contrast to the rather lackluster growth outlook for overall IT spending, Gartner expects enterprise spending on public cloud services to grow from $91 billion worldwide in 2011 to $109 billion in 2012. By 2016, enterprise public cloud services spending will reach $207 billion. Fake anti-piracy warnings hitting UK users with … More →

    newswww.helpnetsecurity.comJul 16, 2012, 12:01 AM
  • The long awaited patch for the CVE-2012-1889 vulnerability that has been heavily exploited in the wild and the exploit for which has even been included in the Blackhole Exploit Kit is not the only big news from the latest Patch Tuesday. Among other things, Microsoft has notified users that it has made available an automated Microsoft Fix it solution (a workaround – not a patch) that disables the Windows Sidebar and Gadgets on supported editions … More →

    newswww.helpnetsecurity.comJul 11, 2012, 2:57 PM
  • Every Patch Tuesday, my inbox fills up with commentary from patch management experts on Microsoft’s latest fixes. Rather than toss them aside, I like to run their analysis as is. With that, here’s the July 2012 breakdown, in which Microsoft released nine bulletins addressing 16 vulnerabilities: Jason Miller, Manager of Research and Development, VMware The […]

    newswww.csoonline.comJul 11, 2012, 1:51 PM
  • Microsoft releases nine security bulletinsHelp Net Security

    The Microsoft Security Bulletin Summary for July 2012 contains nine security bulletins addressing 16 CVEs. Three of the bulletins are rated critical and the other six are rated important. All of the critical bulletins address vulnerabilities where a victim could be exploited if they visit malicious web pages, and should serve as a warning that organizations will continue to face client-side browser related attacks. MS12-043 addresses a vulnerability that is currently being exploited in the … More →

    newswww.helpnetsecurity.comJul 10, 2012, 2:01 PM
  • Patch Tuesday is tomorrow. Expect nine security bulletins, three of them for critical vulnerabilities in Windows and Internet Explorer. If Microsoft sticks to plan, the rest will cover “important” security holes in Office, developer tools and server software. Here’s some analysis from three patch management experts: Wolfgang Kandek, CTO of Qualys: Bulletin 1, rated “critical,” […]

    newswww.csoonline.comJul 9, 2012, 9:05 AM
  • Microsoft to release nine bulletinsHelp Net Security

    The Microsoft Security Bulletin Advance Notification for July 2012 contains nine bulletins, with three listed as “critical” and six listed as “important.” Many are expecting a patch for CVE-2012-1889: a vulnerability in Microsoft XML Core Services, which is currently being exploited in the wild. Microsoft released a temporary fix for this last month, and hopefully organizations will apply that while Microsoft works on a permanent fix; however, it isn’t clear whether that will be issued … More →

    newswww.helpnetsecurity.comJul 6, 2012, 3:49 AM
  • Researchers at AlienVault believe an updated version of the Sykipot Trojan is being used to target the aerospace industry.

    newswww.securityweek.comJul 3, 2012, 7:59 PM
  • An exploit for an unpatched vulnerability in the Microsoft XML Core Services (MSXML) has been incorporated into Blackhole, one of the most widely used Web attack toolkits, according to security researchers from antivirus firm Sophos. The security flaw is identified as CVE-2012-1889 and is what security researchers call a zero-day vulnerability — an actively exploited […]

    newswww.csoonline.comJul 2, 2012, 3:00 PM
  • Here’s an overview of some of last week’s most interesting news, podcasts, interviews and articles: Real life examples on hackers bypassing CAPTCHA Computer-assisted tools and crowd sourcing can easily bypass traditional anti-spam solutions, forcing CAPTCHAs to evolve to address these techniques, according to Imperva. Vulnerabilities in open source WAF ModSecurity During our research of web application firewall evasion issues, we uncovered a flaw in ModSecurity that may lead to complete bypass of the installed rules, … More →

    newswww.helpnetsecurity.comJun 25, 2012, 12:00 AM
  • An unpatched Windows vulnerability considered a critical threat by security experts is being exploited by cybercriminals. Microsoft disclosed the flaw in XML Core Services (MSXML) 3.0, 4.0 and 6.0 June 12 during its monthly release of patches. The security advisory, which was separate from the patch release, offered a workaround for vulnerability CVE-2012-1889, but no […]

    newswww.csoonline.comJun 20, 2012, 3:00 PM
  • The still unpatched Microsoft XML Core Services vulnerability (CVE-2012-1889) that allows attackers to gain the same user rights as the logged on user and execute malicious code remotely is being actively exploited in the wild. According to Sophos, the website of a European aeronautical parts supplier has been recently compromised and found serving a file infected with the code that tries to exploit the aforementioned zero-day. Given that the vulnerability was recently tied to Google’s … More →

    newswww.helpnetsecurity.comJun 20, 2012, 12:09 PM
  • Attack code for two actively exploited vulnerabilities in Microsoft software, one of which has not yet been patched, was integrated into the open-source Metasploit penetration testing framework. One of the vulnerabilities is identified as CVE-2012-1875 and is located in Internet Explorer. Attackers can exploit it to execute malicious code by tricking users into visiting a […]

    newswww.csoonline.comJun 18, 2012, 3:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence