Web 2.0 : Internet Explorer CDwnBindInfo object use-after-free vulnerability (CVE-2012-4792)


Description   Internet explorer (version 6, 7 and 8) is impacted by a critical vulnerability leading to remote code execution and known as CVE-2012-4792. This signature is able to detect and block many variants of the proof of concept that have been publicly released. As a result, it will prevent many automated exploitations. But please notice that given the nature of this vulnerability, an advanced exploitation that bypass this protection may still be possible. Please refer to the security advices provided by Microsoft (link below) if you want to deploy complementary protections for that issue.
     
Default
Configuration
 
Profiles High Medium Low Internet
Action Block Block Block Block
Level Major Major Major Major
     
References     CVE-2012-4792
http://technet.microsoft.com/en-us/security/advisory/2794220
https://community.rapid7.com/community/metasploit/blog/2012/12/29/microsoft-internet-explorer-0-day-marks-the-end-of-2012
     
Available since   ASQ v.5.0.0
     
Protect   Microsoft Internet Explorer "CDwnBindInfo" Use-After-Free Vulnerability


 
 
 
 
 Risk level  
Critical