High severity8.8CISA KEVNVD Advisory· Published Jun 13, 2012· Updated Apr 22, 2026
CVE-2012-1889
CVE-2012-1889
Description
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Affected products
4cpe:2.3:a:microsoft:xml_core_services:3.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:microsoft:xml_core_services:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:xml_core_services:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:xml_core_services:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:xml_core_services:6.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-043nvdPatchVendor Advisory
- technet.microsoft.com/security/advisory/2719615nvdVendor Advisory
- www.us-cert.gov/cas/techalerts/TA12-174A.htmlnvdThird Party AdvisoryUS Government Resource
- www.us-cert.gov/cas/techalerts/TA12-192A.htmlnvdThird Party AdvisoryUS Government Resource
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15195nvdBroken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.