PT-2007-5128 · Microsoft · Internet Explorer
Published
2007-12-11
·
Updated
2021-07-23
·
CVE-2007-3902
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Internet Explorer versions 5.01 through 7
Description:
The issue is related to a use-after-free vulnerability in the CRecalcProperty function, allowing remote attackers to execute arbitrary code. This can be achieved by calling the
setExpression method and then modifying the outerHTML property of an HTML element. The vulnerability exists due to Internet Explorer accessing an object that has not been correctly initialized or that has been deleted, which could be exploited by constructing a specially crafted Web page, potentially leading to remote code execution.Recommendations:
For Microsoft Internet Explorer versions 5.01 through 7, consider applying security patches or updates to fix the vulnerability. As a temporary workaround, restrict access to specially crafted Web pages to minimize the risk of exploitation. Avoid using the
setExpression method in conjunction with modifying the outerHTML property of an HTML element until the issue is resolved.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer