CVE-2012-4792
CISA 기관 조치 기한: 2024-08-13
Microsoft Internet Explorer
Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object.
KEV 필수 조치: The impacted product is end-of-life and should be disconnected if still in use.
공개 익스플로잇 / PoC
- GitHub 공개 PoC 1건 — 대표 레포 ↗
- Exploit-DB: EDB-23785 ↗