‫ Microsoft Internet Explorer Multiple Use-After-Free Vulnerabilities

IRCAD2012112294
ID: IRCAD2012112294
Release Date: 2012-11-13
Criticality level: Highly critical
 
Software:
Microsoft Internet Explorer 9.x
 
Description:
Multiple vulnerabilities have been reported in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system.
1) A use-after-free error within the "CFormElement" class can be exploited to dereference already freed memory.
2) A use-after-free error within the "CTreePos" class can be exploited to dereference already freed memory.
3) A use-after-free error within the "CTreeNode" class can be exploited to dereference already freed memory.
Successful exploitation of the vulnerabilities allows execution of arbitrary code.
 
Solution
Apply updates.
 
Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows 7 for 32-bit Systems
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems
Windows Server 2008 R2 for x64-based Systems Service Pack 1
 
References:
Microsoft (KB2761451):
 
Secunia:
 
 

نظرات

بدون نظر
شما برای نظر دادن باید وارد شوید

نوشته

 
تاریخ ایجاد: 24 آبان 1391

امتیاز

امتیاز شما
تعداد امتیازها:0