PT-2009-4027 · Microsoft · Vista+5
Wushi
·
Published
2009-06-10
·
Updated
2023-12-07
·
CVE-2009-1530
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Internet Explorer 7 for Windows XP SP2 and SP3
Microsoft Internet Explorer 7 for Server 2003 SP2
Microsoft Internet Explorer 7 for Vista Gold, SP1, and SP2
Microsoft Internet Explorer 7 for Server 2008 SP2
Description:
A use-after-free issue allows remote attackers to execute arbitrary code by repeatedly adding HTML document nodes and calling event handlers, which triggers an access of an object that was not properly initialized or is deleted. This could allow an attacker to gain the same user rights as the logged-on user, potentially taking complete control of an affected system if the user has administrative rights.
Recommendations:
For Microsoft Internet Explorer 7 on all affected platforms, update to a version that addresses this issue to prevent exploitation.
As a temporary workaround, consider restricting access to specially crafted Web pages that could trigger the vulnerability until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer
Internet Explorer 7
Server 2003
Server 2008
Vista
Windows Xp