← Back

CVE-2012-1858

nvd nist
Published: Jun 12, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."

Affected (6)

3 products
Lync
Office Communicator
Internet Explorer
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2010
Version 2010
Version 2010
Version 2007 r2
Configuration B
1 vulnerable · 7 platform
Vulnerable SoftwareAffected Versions
Version 8
Running on/withPlatform Versions
Microsoft
Windows 2003 Server
All versions
Microsoft
Windows Server 2003
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Xp
All versions
Microsoft
Windows Xp
All versions
Configuration C
1 vulnerable · 11 platform
Vulnerable SoftwareAffected Versions
Version 9
Running on/withPlatform Versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
Version r2
Microsoft
Windows Vista
All versions
Microsoft
Windows Vista
All versions

Timeline

No history available yet.