|
|
|
|
| |
Credit:
The information has been provided by Nicolas Joly .
The original article can be found at: http://seclists.org/bugtraq/2011/Feb/141
|
| |
Vulnerable Systems:
* Microsoft Internet Explorer 8
* Microsoft Internet Explorer 7
* Microsoft Internet Explorer 6
* Microsoft Windows 7
* Microsoft Windows Server 2003
* Microsoft Windows Server 2008
* Microsoft Windows Vista
* Microsoft Windows XP Professional x64 Edition Service Pack 2
* Microsoft Windows XP Service Pack 3
The vulnerability is caused by a dangling pointer in the "mshtml.dll" library when handling certain object manipulations, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a malicious web page.
Patch Availability:
Apply the MS11-003 security update:
http://www.microsoft.com/technet/security/bulletin/ms11-003.mspx
CVE Information:
CVE-2011-0036
Disclosure Timeline:
2010-06-15 - Vulnerability Discovered
2010-xx-xx - Vulnerability rediscovered by third parties
2011-02-08 - MS11-003 security update available
|
|
|
|
|