Lucene search

K
cveMicrosoftCVE-2012-2523
HistoryAug 15, 2012 - 1:55 a.m.

CVE-2012-2523

2012-08-1501:55:01
CWE-189
microsoft
web.nvd.nist.gov
108
cve-2012-2523
microsoft internet explorer
integer overflow
remote code execution
vulnerability
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

Low

EPSS

0.854

Percentile

98.6%

Integer overflow in Microsoft Internet Explorer 8 and 9, JScript 5.8, and VBScript 5.8 on 64-bit platforms allows remote attackers to execute arbitrary code by leveraging an incorrect size calculation during object copying, aka β€œJavaScript Integer Overflow Remote Code Execution Vulnerability.”

Affected configurations

Nvd
Node
microsoftinternet_explorerMatch8
OR
microsoftinternet_explorerMatch9
OR
microsoftjscriptMatch5.8
OR
microsoftvbscriptMatch5.8-x64
VendorProductVersionCPE
microsoftinternet_explorer8cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*
microsoftinternet_explorer9cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
microsoftjscript5.8cpe:2.3:a:microsoft:jscript:5.8:*:*:*:*:*:*:*
microsoftvbscript5.8cpe:2.3:a:microsoft:vbscript:5.8:-:x64:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

Low

EPSS

0.854

Percentile

98.6%