|
|
|
Credit:
The information has been provided by Nicolas Joly.
The original article can be found at: http://seclists.org/bugtraq/2011/Apr/159
|
|
Vulnerable Systems:
* Microsoft Internet Explorer 8
* Microsoft Windows XP Service Pack 3
* Microsoft Windows Server 2003 Service Pack 2
* Microsoft Windows Vista Service Pack 2
* Microsoft Windows Server 2008 Service Pack 2
* Microsoft Windows 7 Service Pack 1
* Microsoft Windows Server 2008 R2 Service Pack 1
The vulnerability is caused by a use-after-free error in the "CObjectElement::OnPropertyChange()" function within the MSHTML library when handling objects, which could be exploited by remote attackers to compromise a vulnerable system by tricking a user into visiting a specially crafted web page.
Patch Availability:
Apply the MS11-018 security update.
http://www.microsoft.com/technet/security/bulletin/ms11-018.mspx
CVE Information:
CVE-2011-1345
Disclosure Timeline:
2011-01-22 - Vulnerability Discovered
2011-04-12 - MS11-018 security update available
|
|
|
|