Oval Definition:oval:org.mitre.oval:def:15240
Revision Date:2014-08-18Version:48
Title:Layout memory corruption vulnerability - MS12-052
Description:Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not initialized or (2) is deleted, aka "Layout Memory Corruption Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2012-1526
Platform(s):Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Internet Explorer 6
Microsoft Internet Explorer 7
Definition Synopsis
  • IE6 + xp/2k3 with vulnerable files
  • Microsoft Internet Explorer 6 is installed
  • AND vulnerable os with vulnerable files
  • XP(32) and vulnerable file version
  • Microsoft Windows XP (32-bit) is installed
  • AND Check if the version of mshtml.dll is less than 6.0.2900.6266
  • OR XP64 or 2k3 and vulnerable file version
  • XP 64 / 2k3
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • OR Microsoft Windows Server 2003 (ia64) Gold is installed
  • AND Check if the version of mshtml.dll is less than 6.0.3790.5029
  • OR IE7 + xp/2k3/vista/2k8 and vulnerable file version
  • Microsoft Internet Explorer 7 is installed
  • AND vulnerable os with vulnerable files
  • XP/2K3 and vulnerable file version
  • Win XP / 2K3
  • Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • OR Microsoft Windows Server 2003 (ia64) Gold is installed
  • AND LDR/GDR
  • Check if the version of mshtml.dll is less than 7.0.6000.17112
  • OR IE7 + Vista / 2k8 and vulnerable file version
  • Vista / 2K8 and vulnerable file versions
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND Check for LDR/ GDR
  • Check if the version of mshtml.dll is less than 7.0.6002.18658
  • BACK