peter bassill · operator
$ cve CVE-2012-4787 JSON

CVE-2012-4787

9.0
CRITICAL · CVSS 3.1 · EPSS 17.6% (pctl 97)

Patch early

EPSS 17.6% — above the 10% action threshold.

Description

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly initialized or (2) is deleted, aka "Improper Ref Counting Use After Free Vulnerability."

Scoring

CVSS9.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS17.57% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploitnone known
Published2012-12-12
Last modified2026-06-16

Affected (7)

VendorProduct
microsoftinternet explorer
microsoftwindows 7
microsoftwindows 8
microsoftwindows rt
microsoftwindows server 2008
microsoftwindows server 2012
microsoftwindows vista

References

→ the Explorer  ·  watch your stack  ·  NVD