logo

CVE-2012-1889 Is Still Alive!

ID: 4cbd23a6-1fef-5302-b797-753fd976e2c5

STIX ID: report--4cbd23a6-1fef-5302-b797-753fd976e2c5

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler identified a malicious Chinese website (http://wm.17wan.info:9999/...) that exploits CVE-2012-1889 via highly obfuscated JavaScript which performs heap-spray and decodes shellcode to achieve remote code execution in Internet Explorer; the site crashes IE, attempts to evade AV through obfuscation, drops a malicious RAR and contacts external domains (js.users.51.la, web1.51.la:82). Although the vulnerability is from 2012, the report shows it is still being actively exploited against online gamers and includes decoded script analysis and observed HTTP transactions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.