Skip to main content

Microsoft Internet Explorer Circular Memory References Use-after-free Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 6 Jan 2011 4935 Views

RISK: Medium Risk

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a use-after-free error within the "mshtml.dll" library when handling circular references between JScript objects and Document Object Model (DOM) objects, which could allow remote attackers to execute arbitrary code via a specially crafted web page.

Successful exploitation allows execution of arbitrary code.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Internet Explorer 8
  • Microsoft Windows 7
  • Microsoft Windows Server 2008 Service Pack 2
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Vista Service Pack 2
  • Microsoft Windows Server 2003 Service Pack 2
  • Microsoft Windows XP Service Pack 3

Solutions

  • It is not aware of any vendor-supplied patch.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link