CVE-2012-1889: Microsoft XML Core Services Memory Corruption Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-06-08. EPSS: 83.5% chance of exploitation in the next 30 days.

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

Affected products

  • Microsoft XML Core Services: version 3.0 only; version 4.0 only; version 6.0 only; version 5.0 only

Published 2012-06-13. Last modified 2026-06-16.