CVE-2012-1858: Microsoft Internet Explorer

Medium severity, CVSS 4.3. EPSS: 22% chance of exploitation in the next 30 days.

The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."

Affected products

  • Microsoft Internet Explorer: version 8 only; version 9 only
  • Microsoft Lync: version 2010 only
  • Microsoft Office Communicator: version 2007 only

Published 2012-06-12. Last modified 2026-06-16.