CVE-2012-4969 is a critical use-after-free vulnerability in Microsoft Internet Explorer versions 6 through 9, specifically within the CMshtmlEd::Exec function in mshtml.dll, affecting various Windows operating systems. With a CVSS score of 8.1 (HIGH), it allows remote attackers to execute arbitrary code via a crafted website, requiring no user interaction beyond visiting the malicious page. This vulnerability has been actively exploited in the wild since September 2012, with publicly available Metasploit modules and significant community discussion and media coverage confirming its widespread impact and exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:* | ||
8CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:* | ||
9CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.