← Back

CVE-2012-1889

nvd nist
Published: Jun 13, 2012Modified: Apr 22, 2026CISA KEV

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

Affected (4)

1 product
Xml Core Services
Configuration A
3 vulnerable · 11 platform
Vulnerable SoftwareAffected Versions
Microsoft
Version 3.0
Version 4.0
Version 6.0
Running on/withPlatform Versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 8
All versions
Microsoft
Windows Server 2003
All versions
Microsoft
Windows Server 2003
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
Version r2
Microsoft
Windows Server 2008
Version r2 sp1
Microsoft
Windows Server 2012
All versions
Microsoft
Windows Vista
All versions
Microsoft
Windows Xp
All versions
Configuration B
1 vulnerable · 14 platform
Vulnerable SoftwareAffected Versions
Version 5.0
Running on/withPlatform Versions
Microsoft
Expression Web
Version 2
Microsoft
Expression Web
Version sp1
Microsoft
Groove
Version 2007 sp2
Microsoft
Groove
Version 2007 sp3
Microsoft
Groove Server
Version 2007 sp2
Microsoft
Groove Server
Version 2007 sp3
Microsoft
Office
Version 2003 sp3
Microsoft
Office
Version 2007 sp2
Microsoft
Office
Version 2007 sp3
Microsoft
Office Compatibility Pack
All versions
Microsoft
Office Compatibility Pack
All versions
Microsoft
Office Word Viewer
All versions
Microsoft
Sharepoint Server
Version 2007 sp2
Microsoft
Sharepoint Server
Version 2007 sp3

References (11)

Source: secure@microsoft.com
Vendor Advisory
Source: secure@microsoft.com
Third Party AdvisoryUS Government Resource
Source: secure@microsoft.com
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.