CVE-2012-4792Active Exploitation(microsoft / internet_explorer)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Prioritize remediation for microsoft internet_explorer systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-08-13. The impacted product is end-of-life and should be disconnected if still in use.

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • internet_explorer
  • windows_7
  • windows_server_2003
  • windows_server_2008

Threat summary

  • Active exploitation appears in 2 classified signals
  • 4 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
internet_explorerwindows_7windows_server_2003windows_server_2008windows_vistawindows_xp

4 versions affected across 6 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-01: 4Active Exploitation · 2026-05-01: 2Technical Details · 2026-05-01: 305-01
Signal classification2 categories
Active Exploitation
250.0%
Disclosure
250.0%
Referenced assets1 URL
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA added CVE-2012-4792 to the Known Exploited Vulnerabilities (KEV) catalog on 2024-07-23, signaling confirmed in-the-wild exploitation CISA KEV. The bug is a use-after-free in Microsoft Internet Explorer that enables remote code execution via a crafted…

    Post summary

    CISA has listed CVE-2012-4792 in its KEV catalog, confirming it is being exploited in the wild, with the vulnerability being a use‑after‑free in Internet Explorer that can lead to remote code execution.

    1000040
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2012-4792: CISA added a remote code execution use-after-free in Microsoft Internet Explorer (CVE-2012-4792) to KEV. IE is EOL; disconnect by 2024-08-13.

    Post summary

    CISA added CVE-2012-4792, a remote code execution use‑after‑free in IE, to its KEV list, noting the browser is end‑of‑life and advising disconnection by 2024‑08‑13.

    1000025
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Technical detail CVE-2012-4792 is a browser memory-lifetime bug where Internet Explorer accesses a freed or improperly allocated object, leading to a use-after-free condition NVD CVE-2012-4792. The vulnerability can be triggered remotely by a crafted website, which means a…

    Post summary

    The post delivers technical details on CVE‑2012‑4792—a use‑after‑free flaw in Internet Explorer that can be triggered remotely—without discussing PoCs, exploits, patches, or active exploitation.

    1000037
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2012-4792-internet-explorer #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet points to a research page labelled "active exploit" for CVE‑2012‑4792, hinting that the Internet Explorer vulnerability is currently being exploited in the wild.

    0000028
    152 followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftinternet_explorer6--
Appmicrosoftinternet_explorer7--
Appmicrosoftinternet_explorer8--
OSmicrosoftwindows_7---
OSmicrosoftwindows_7--x64
OSmicrosoftwindows_7--x86
OSmicrosoftwindows_server_2003---
OSmicrosoftwindows_server_2008--itanium
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--itanium
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_vista---
OSmicrosoftwindows_xp--x64
OSmicrosoftwindows_xp--x64
OSmicrosoftwindows_xp---

Explore more