Executive Summary
| Summary | |
|---|---|
| Title | Microsoft Internet Explorer HTML object memory corruption vulnerability |
| Informations | |||
|---|---|---|---|
| Name | VU#492515 | First vendor Publication | 2010-01-14 |
| Vendor | VU-CERT | Last vendor Modification | 2010-01-21 |
| Severity (Vendor) | N/A | Revision | M |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 9.3 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Medium |
| Cvss Expoit Score | 8.6 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Vulnerability Note VU#492515Microsoft Internet Explorer HTML object memory corruption vulnerabilityOverviewAn invalid pointer reference within Microsoft Internet Explorer may lead to execution of arbitrary code.I. DescriptionMicrosoft Internet Explorer contains a memory corruption vulnerability, which can result in an invalid pointer being accessed after an object is incorrectly initialized or has been deleted. In certain circumstances, the invalid pointer access can be leveraged by an attacker to execute arbitrary code. This vulnerability is being actively exploited, and exploit code is publically available.Please see Microsoft Security Advisory 979352 for further information. II. ImpactBy convincing a user to load a specially crafted HTML document or Microsoft Office document, a remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial-of-service condition.III. SolutionApply an updateMicrosoft has released an update to address the issue. See Microsoft Security Bulletin MS10-002 for more information. Users are encouraged to consider additional mitigations listed in Microsoft Security Advisory 979352: Systems Affected
References CreditThis vulnerability was reported by Microsoft. Microsoft credits Google Inc., MANDIANT, Adobe, and McAfee. This document was written by David Warren. Other Information
|
Original Source
| Url : http://www.kb.cert.org/vuls/id/492515 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-399 | Resource Management Errors |
OVAL Definitions
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 4 |
SAINT Exploits
| Description | Link |
|---|---|
| Internet Explorer Eventparam use-after-free vulnerability | More info here |
ExploitDB Exploits
| id | Description |
|---|---|
| 2010-01-17 | Internet Explorer Aurora Exploit |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 61697 | Microsoft IE mshtml.dll Use-After-Free Arbitrary Code Execution (Aurora) |
Metasploit Database
| id | Description |
|---|---|
| 2010-01-14 | Internet Explorer "Aurora" Memory Corruption |
Alert History
| Date | Informations |
|---|---|
| 2013-05-11 00:57:08 |
|

VU#492515
(Critical)









