Skip to main content

Microsoft Internet Explorer Remote Code Execution Vulnerability

Last Update Date: 9 Dec 2014 09:19 Release Date: 9 Dec 2014 3674 Views

RISK: Extremely High Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability has been identified in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a use-after-free error when handling CElement objects and can be exploited to cause memory corruption via a specially crafted HTML element with "display:run-in" style applied.

Successful exploitation of this vulnerability may allow execution of arbitrary code.

 

Note: No official solution is currently available.


Impact

  • Remote Code Execution

System / Technologies affected

  • Internet Explorer 9.x

Solutions

  • No official solution is currently available.

Vulnerability Identifier


Source


Related Link