PT-2009-4027 · Microsoft · Vista+5

Wushi

·

Published

2009-06-10

·

Updated

2023-12-07

·

CVE-2009-1530

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Explorer 7 for Windows XP SP2 and SP3 Microsoft Internet Explorer 7 for Server 2003 SP2 Microsoft Internet Explorer 7 for Vista Gold, SP1, and SP2 Microsoft Internet Explorer 7 for Server 2008 SP2
Description: A use-after-free issue allows remote attackers to execute arbitrary code by repeatedly adding HTML document nodes and calling event handlers, which triggers an access of an object that was not properly initialized or is deleted. This could allow an attacker to gain the same user rights as the logged-on user, potentially taking complete control of an affected system if the user has administrative rights.
Recommendations: For Microsoft Internet Explorer 7 on all affected platforms, update to a version that addresses this issue to prevent exploitation. As a temporary workaround, consider restricting access to specially crafted Web pages that could trigger the vulnerability until a patch is available.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2009-1530

Affected Products

Internet Explorer
Internet Explorer 7
Server 2003
Server 2008
Vista
Windows Xp