Microsoft Internet Explorer Circular Memory References Use-after-free Vulnerability
Last Update Date:
28 Jan 2011
Release Date:
6 Jan 2011
5723
Views
RISK: Medium Risk
A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a use-after-free error within the "mshtml.dll" library when handling circular references between JScript objects and Document Object Model (DOM) objects, which could allow remote attackers to execute arbitrary code via a specially crafted web page.
Successful exploitation allows execution of arbitrary code.
Impact
- Remote Code Execution
System / Technologies affected
- Microsoft Internet Explorer 8
- Microsoft Windows 7
- Microsoft Windows Server 2008 Service Pack 2
- Microsoft Windows Server 2008 R2
- Microsoft Windows Vista Service Pack 2
- Microsoft Windows Server 2003 Service Pack 2
- Microsoft Windows XP Service Pack 3
Solutions
- It is not aware of any vendor-supplied patch.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with