TA13-015A: Microsoft Releases Update for Internet Explorer Vulnerability CVE-2012-4792


Extraordinary Robot
News Feed
Original release date: January 15, 2013 | Last revised: February 06, 2013
[h=3]Systems Affected[/h]
    • Microsoft Internet Explorer 6
    • Microsoft Internet Explorer 7
    • Microsoft Internet Explorer 8
[h=3]Overview[/h] Microsoft has released Security Bulletin MS13-008 to address the CButton use-after-free vulnerability (CVE-2012-4792).
[h=3]Description[/h] Microsoft Internet Explorer versions 6, 7, and 8 are susceptible to a use-after-free vulnerability. This vulnerability is being actively exploited in the wild. Microsoft has released Security Bulletin MS13-008 to address this vulnerability.
Additional information is available in Vulnerability Note VU#154201.
[h=3]Impact[/h] A remote, unauthenticated attacker could execute arbitrary code, cause a denial of service, or gain unauthorized access to your files or system.
[h=3]Solution[/h] US-CERT recommends that Internet Explorer users run Windows Update as soon as possible to apply the MS13-008 update.
[h=3]Revision History[/h]
  • January 15, 2013: Initial release
[HR][/HR] This product is provided subject to this Notification and this Privacy & Use policy.

Syndicated from the United States Security Readiness Team (US-CERT). More...

This website is not affiliated, owned, or endorsed by Microsoft Corporation. It is a member of the Microsoft Partner Program.