CVE-2012-1889

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

Scoring

Severity
HIGH
CVSS base score
8.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS probability
92.78%
CISA KEV
Known exploited vulnerability
Published
2012-06-13
Last modified
2026-09-16

Affected products

Markdown version · Browse all CVEs