Microsoft has issued a security advisory that describes a vulnerability in its XML module. McAfee has also observed that the vulnerability is being actively exploited in the wild. The vulnerability exists when the function “msxml3!_dispatchImpl::InvokeHelper” in Microsoft’s XML attempts to access an object in memory that has not been initialized, allowing attacker to execute arbitrary Read more…
Tags: CVE 2012-1889, iframe, Microsoft XML Core Services, uninitialized local variable, vulnerability
Posts tagged under Microsoft XML Core Services