Microsoft Internet Explorer OnReadyStateChange Remote Code Execution Vulnerability
10 Apr. 2012
Summary
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "SelectAll Remote Code Execution Vulnerability.
Credit:
The information has been provided by Jose Antonio Vazquez Gonzalez.
Vulnerable Systems:
* Internet Explorer 9 and prior
A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted. The vulnerability may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Vendor Status:
Microsoft had issued an update for this vulnerability