TA13-015A: Microsoft Releases Update for Internet Explorer Vulnerability CVE-2012-4792

Discussion in 'Security Alerts' started by News, Feb 27, 2013.

  1. News

    News Extraordinary Robot
    News Feed

    Jun 27, 2006
    Likes Received:
    Original release date: January 15, 2013 | Last revised: February 06, 2013
    [h=3]Systems Affected[/h]
      • Microsoft Internet Explorer 6
      • Microsoft Internet Explorer 7
      • Microsoft Internet Explorer 8
    [h=3]Overview[/h] Microsoft has released Security Bulletin MS13-008 to address the CButton use-after-free vulnerability (CVE-2012-4792).
    [h=3]Description[/h] Microsoft Internet Explorer versions 6, 7, and 8 are susceptible to a use-after-free vulnerability. This vulnerability is being actively exploited in the wild. Microsoft has released Security Bulletin MS13-008 to address this vulnerability.
    Additional information is available in Vulnerability Note VU#154201.
    [h=3]Impact[/h] A remote, unauthenticated attacker could execute arbitrary code, cause a denial of service, or gain unauthorized access to your files or system.
    [h=3]Solution[/h] US-CERT recommends that Internet Explorer users run Windows Update as soon as possible to apply the MS13-008 update.
    [h=3]Revision History[/h]
    • January 15, 2013: Initial release
    [HR][/HR] This product is provided subject to this Notification and this Privacy & Use policy.

    Syndicated from the United States Security Readiness Team (US-CERT). More...

Share This Page