How to Buy
This script is Copyright (C) 2012-2016 Tenable Network Security, Inc.
Arbitrary code can be executed on the remote host through the installed
JScript and VBScript scripting engines.
The installed versions of the JScript and VBScript scripting engines
contain an integer overflow vulnerability that can occur when the
scripting engines process a script in a web page and attempt to
calculate the size of an object in memory during a copy operation.
By tricking a user on the affected system into visiting a malicious web
site, an attacker may be able to exploit this issue to execute arbitrary
code subject to the user's privileges.
See also :
Microsoft has released a set of patches for 64-bit editions of Windows
XP, 2003, Vista, 2008, 7, and 2008 R2.
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 7.7
Public Exploit Available : true
Family: Windows : Microsoft Bulletins
Nessus Plugin ID: 61531 ()
Bugtraq ID: 54945
CVE ID: CVE-2012-2523
Get Nessus Professional to scan unlimited IPs, run compliance checks & more
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.