MEDIUM · 4.3

CVE-2012-1858

The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, wh...

Vulnerability Description

The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MicrosoftLync2010
MicrosoftOffice Communicator2007
MicrosoftInternet Explorer8
MicrosoftWindows 2003 ServerAll versions
MicrosoftWindows 7All versions
MicrosoftWindows Server 2003All versions
MicrosoftWindows Server 2008All versions
MicrosoftWindows VistaAll versions
MicrosoftWindows XpAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-1858?

CVE-2012-1858 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, wh...

How severe is CVE-2012-1858?

CVE-2012-1858 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-1858?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Lync, Microsoft Office Communicator, Microsoft Internet Explorer, Microsoft Windows 2003 Server, Microsoft Windows 7.