CVE-2012-4969: Microsoft Internet Explorer Use-After-Free Vulnerability
High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2022-06-08. EPSS: 80.3% chance of exploitation in the next 30 days.
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
Affected products
- Microsoft Internet Explorer: version 6 only; version 7 only; version 8 only; version 9 only
Published 2012-09-18. Last modified 2026-06-16.