<< Back
CVE Number Vulnerability Product Severity Date
MS12-043 Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2722479) Microsoft XML Critical 11-07-2012

Technical Information

Brief overview of the risk:
This security update resolves a publicly disclosed vulnerability in Microsoft XML Core Services. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer.
Detailed Information on the risk:

A remote code execution vulnerability exists in the way that Microsoft XML Core Services handles objects in memory. The vulnerability could allow remote code execution if a user views a website that contains specially crafted content. An attacker who successfully exploited this vulnerability could take complete control of an affected system.


Further information on this exploit is available at : MS12-043

Affected Software

Microsoft XML Core Services 3.0
Microsoft XML Core Services 6.0
Microsoft XML Core Services 4.0
Microsoft XML Core Services 5.0