CVE detail
CVE-2012-1889
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
24 source links · newest first
The 5th installment in a series of posts tracking web-based threats over time from our Email Link Analysis (ELINK) system., specifically, statistics pertaining to malicious URLs, domains, exploit kits, vulnerabilities, and phishing scams.
vendorunit42.paloaltonetworks.comNov 1, 2019, 1:00 PMOur Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.
vendorunit42.paloaltonetworks.comDec 27, 2018, 2:00 PMJapanese commercial and critical infrastructure organizations have been targeted a long-running campaign dubbed Operation Dust Storm. Security firm Cylance have uncovered a long-running hacking campaign dubbed ‘Operation Dust Storm’ targeting commercial and critical infrastructure organizations in Japan. Threat actors behind the Operation Dust Storm have been active since at least 2010, the hackers targeted several organizations in Japan, […]
newssecurityaffairs.comFeb 24, 2016, 7:07 AMCommercial and critical infrastructure organizations in Japan have been targeted in a multi-year campaign dubbed by researchers “Operation Dust Storm.”
newswww.securityweek.comFeb 23, 2016, 6:43 PM- Elderwood Attack Platform Linked to Multiple Internet Explorer Zero-Day Attacks: SymantecSecurityWeek
Researchers at Symantec say the Elderwood attack platform is at the center of numerous zero-day attacks launched by hacker crews around the world this year.
newswww.securityweek.comMay 15, 2014, 5:46 PM The simplicity of the malware that paralyzed the computer networks of three banks and two broadcasters in technically sophisticated South Korea is a warning that U.S. corporations need to rethink security. The cybercriminals did nothing out of the ordinary in penetrating the organizations’ defenses on Wednesday. They used existing malware called “DarkSeoul,” changed its signature […]
newswww.csoonline.comMar 22, 2013, 3:00 PMResearchers at AlienVault shed some light on the evolution of the Sykipot malware attacks. The Sykipot attacks have exploited a number of zero-days during the past few years, including vulnerabilities affecting Adobe Reader, Adobe Flash Player and Microsoft Internet Explorer.
newswww.securityweek.comMar 21, 2013, 6:54 PMU.S companies and government agencies can learn from the large-scale disruptions that have simultaneously hit several banks and media outlets in South Korea in the last 24 hours. Early analyses by security firms suggest that the attacks were carried out using previously known vulnerabilities and exploits. So while considerable attention is being paid to whether […]
newswww.csoonline.comMar 20, 2013, 3:00 PM- How the security threat landscape will evolve this yearHelp Net Security
Where 2012 was a period of great innovation amongst cybercriminals and hackers – many of whom keenly develop new and hybridized attack vectors that build on a constantly expanding range of extensible code environments seen running on Windows and Apple Mac platforms – 2013 is likely to go down in the darkware IT history books as a period of consolidation. This trend will be driven, we predict, by the not inconsiderable fact that the incredible … More →
newswww.helpnetsecurity.comJan 16, 2013, 2:00 PM Researchers at Symantec say the waterholing attacks utilizing the recently-publicized Internet Explorer zero-day are tied to a gang responsible for a spate of similar kinds of attacks.
newswww.securityweek.comJan 4, 2013, 2:29 PMThe latest Java vulnerability has been integrated into both Black Hole and Gong Da exploit kits, making it easier for cyber-criminals to launch attacks exploiting the flaw, a security researcher said.
newswww.securityweek.comNov 22, 2012, 12:36 PMAn elite hacker group targeting defense industry sub-contractors has an inexhaustible supply of zero-days, or vulnerabilities that have yet to be publicized, much less patched, Symantec said today. In a blog post, the security firm said, “The group seemingly has an unlimited supply of zero-day vulnerabilities.” Symantec also laid out its analysis of the gang, […]
newswww.csoonline.comSep 7, 2012, 3:00 PM- Week in review: Yahoo password leak, multi-platform backdoor, Microsoft revokes its code-signing certificatesHelp Net Security
Here’s an overview of some of last week’s most interesting news, videos, interviews and articles: Worldwide IT spending to surpass $3.6 trillion in 2012 In contrast to the rather lackluster growth outlook for overall IT spending, Gartner expects enterprise spending on public cloud services to grow from $91 billion worldwide in 2011 to $109 billion in 2012. By 2016, enterprise public cloud services spending will reach $207 billion. Fake anti-piracy warnings hitting UK users with … More →
newswww.helpnetsecurity.comJul 16, 2012, 12:01 AM - Microsoft revokes 28 of its code-signing certificatesHelp Net Security
The long awaited patch for the CVE-2012-1889 vulnerability that has been heavily exploited in the wild and the exploit for which has even been included in the Blackhole Exploit Kit is not the only big news from the latest Patch Tuesday. Among other things, Microsoft has notified users that it has made available an automated Microsoft Fix it solution (a workaround – not a patch) that disables the Windows Sidebar and Gadgets on supported editions … More →
newswww.helpnetsecurity.comJul 11, 2012, 2:57 PM Every Patch Tuesday, my inbox fills up with commentary from patch management experts on Microsoft’s latest fixes. Rather than toss them aside, I like to run their analysis as is. With that, here’s the July 2012 breakdown, in which Microsoft released nine bulletins addressing 16 vulnerabilities: Jason Miller, Manager of Research and Development, VMware The […]
newswww.csoonline.comJul 11, 2012, 1:51 PM- Microsoft releases nine security bulletinsHelp Net Security
The Microsoft Security Bulletin Summary for July 2012 contains nine security bulletins addressing 16 CVEs. Three of the bulletins are rated critical and the other six are rated important. All of the critical bulletins address vulnerabilities where a victim could be exploited if they visit malicious web pages, and should serve as a warning that organizations will continue to face client-side browser related attacks. MS12-043 addresses a vulnerability that is currently being exploited in the … More →
newswww.helpnetsecurity.comJul 10, 2012, 2:01 PM - Patch Tuesday preview, July 2012CSO Online
Patch Tuesday is tomorrow. Expect nine security bulletins, three of them for critical vulnerabilities in Windows and Internet Explorer. If Microsoft sticks to plan, the rest will cover “important” security holes in Office, developer tools and server software. Here’s some analysis from three patch management experts: Wolfgang Kandek, CTO of Qualys: Bulletin 1, rated “critical,” […]
newswww.csoonline.comJul 9, 2012, 9:05 AM - Microsoft to release nine bulletinsHelp Net Security
The Microsoft Security Bulletin Advance Notification for July 2012 contains nine bulletins, with three listed as “critical” and six listed as “important.” Many are expecting a patch for CVE-2012-1889: a vulnerability in Microsoft XML Core Services, which is currently being exploited in the wild. Microsoft released a temporary fix for this last month, and hopefully organizations will apply that while Microsoft works on a permanent fix; however, it isn’t clear whether that will be issued … More →
newswww.helpnetsecurity.comJul 6, 2012, 3:49 AM Researchers at AlienVault believe an updated version of the Sykipot Trojan is being used to target the aerospace industry.
newswww.securityweek.comJul 3, 2012, 7:59 PMAn exploit for an unpatched vulnerability in the Microsoft XML Core Services (MSXML) has been incorporated into Blackhole, one of the most widely used Web attack toolkits, according to security researchers from antivirus firm Sophos. The security flaw is identified as CVE-2012-1889 and is what security researchers call a zero-day vulnerability — an actively exploited […]
newswww.csoonline.comJul 2, 2012, 3:00 PM- Week in review: Origins of Flame revealed, Windows 8 security, and active exploitation of state-sponsored 0-dayHelp Net Security
Here’s an overview of some of last week’s most interesting news, podcasts, interviews and articles: Real life examples on hackers bypassing CAPTCHA Computer-assisted tools and crowd sourcing can easily bypass traditional anti-spam solutions, forcing CAPTCHAs to evolve to address these techniques, according to Imperva. Vulnerabilities in open source WAF ModSecurity During our research of web application firewall evasion issues, we uncovered a flaw in ModSecurity that may lead to complete bypass of the installed rules, … More →
newswww.helpnetsecurity.comJun 25, 2012, 12:00 AM An unpatched Windows vulnerability considered a critical threat by security experts is being exploited by cybercriminals. Microsoft disclosed the flaw in XML Core Services (MSXML) 3.0, 4.0 and 6.0 June 12 during its monthly release of patches. The security advisory, which was separate from the patch release, offered a workaround for vulnerability CVE-2012-1889, but no […]
newswww.csoonline.comJun 20, 2012, 3:00 PM- Compromised website serving “state-sponsored” 0-day exploitHelp Net Security
The still unpatched Microsoft XML Core Services vulnerability (CVE-2012-1889) that allows attackers to gain the same user rights as the logged on user and execute malicious code remotely is being actively exploited in the wild. According to Sophos, the website of a European aeronautical parts supplier has been recently compromised and found serving a file infected with the code that tries to exploit the aforementioned zero-day. Given that the vulnerability was recently tied to Google’s … More →
newswww.helpnetsecurity.comJun 20, 2012, 12:09 PM Attack code for two actively exploited vulnerabilities in Microsoft software, one of which has not yet been patched, was integrated into the open-source Metasploit penetration testing framework. One of the vulnerabilities is identified as CVE-2012-1875 and is located in Internet Explorer. Attackers can exploit it to execute malicious code by tricking users into visiting a […]
newswww.csoonline.comJun 18, 2012, 3:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2013-0007CVSS 9.3 · Critical
Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka…
- CVE-2013-0006CVSS 8.8 · High
Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka…
- CVE-2008-4033CVSS 4.3 · Medium
Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attack…
- CVE-2013-3918CVSS 8.8 · High
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R…
- CVE-2013-3163CVSS 8.8 · High
Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet E…
- CVE-2013-3129CVSS 7.8 · High
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows X…