Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution


Updated: 2012-06-15 (GMT +8)

As a member of the Microsoft Active Protection Program (MAPP), Broadweb provides its customers with updated software protection information to address vulnerability exposures issued by Microsoft Security Advisory.

The vulnerability exists when MSXML attempts to access an object in memory that has not been initialized, which may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the logged-on user.

Broadweb protects against this vulnerability with the latest release signature.
Reference :
Microsoft Security Advisory (2719615)
CVE-2012-1889
CVE-2012-1881 (MS12-037)
CVE-2012-1880 (MS12-037)
CVE-2012-1879 (MS12-037)
CVE-2012-1878 (MS12-037)
CVE-2012-1877 (MS12-037)
CVE-2012-1876 (MS12-037)
CVE-2012-1875 (MS12-037)
CVE-2012-1874 (MS12-037)
CVE-2012-1873 (MS12-037)
CVE-2012-1858 (MS12-037)
CVE-2012-1523 (MS12-037)
CVE-2012-1855 (MS12-038)
CVE-2012-1854 (MS12-039)
CVE-2012-1857 (MS12-040)
CVE-2012-1849 (MS12-043)