VYPR
Unrated severityNVD Advisory· Published Jun 12, 2012· Updated Apr 29, 2026

CVE-2012-1858

CVE-2012-1858

Description

The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."

Affected products

6
  • Microsoft/Lync3 versions
    cpe:2.3:a:microsoft:lync:2010:*:attendee:*:*:*:*:*+ 2 more
    • cpe:2.3:a:microsoft:lync:2010:*:attendee:*:*:*:*:*
    • cpe:2.3:a:microsoft:lync:2010:*:x64:*:*:*:*:*
    • cpe:2.3:a:microsoft:lync:2010:*:x86:*:*:*:*:*
  • cpe:2.3:a:microsoft:office_communicator:2007:r2:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.