Executive Summary
| Summary | |
|---|---|
| Title | Microsoft Internet Explorer iepeers.dll use-after-free vulnerability |
| Informations | |||
|---|---|---|---|
| Name | VU#744549 | First vendor Publication | 2010-03-09 |
| Vendor | VU-CERT | Last vendor Modification | 2010-03-30 |
| Severity (Vendor) | N/A | Revision | M |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 9.3 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Medium |
| Cvss Expoit Score | 8.6 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Vulnerability Note VU#744549Microsoft Internet Explorer iepeers.dll use-after-free vulnerabilityOverviewMicrosoft Internet Explorer contains a use-after-free vulnerability in the iepeers.dll file, which may allow a remote, unauthenticated attacker to execute arbitrary code.I. DescriptionMicrosoft Internet Explorer provides support for Web Folders and printing through the use of the iepeers.dll component. According to Microsoft Security Advisory (981374), the iepeers.dll contains a vulnerability in the use of a pointer after an object is freed. Microsoft reports that the vulnerability, which affects Internet Explorer 6 and 7, has been reported publicly.Exploit code for this vulnerability is publicly available. This vulnerability is currently being exploited in the wild. II. ImpactBy convincing a user to load a specially crafted HTML document or Microsoft Office document, a remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial-of-service condition.III. SolutionApply an updateThis issue is addressed in Microsoft Security Bulletin MS10-018, which modifies the way Internet Explorer handles objects in memory. Systems Affected
References CreditThanks to Microsoft for reporting this vulnerability. This document was written by Will Dormann. Other Information
|
Original Source
| Url : http://www.kb.cert.org/vuls/id/744549 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-399 | Resource Management Errors |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:8446 | |||
| Oval ID: | oval:org.mitre.oval:def:8446 | ||
| Title: | Uninitialized Memory Corruption Vulnerability (CVE-2010-0806) | ||
| Description: | Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2010-0806 |
Version: | 2 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 |
Product(s): | Microsoft Internet Explorer 6 Microsoft Internet Explorer 7 |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 2 | |
| Os | 1 | |
| Os | 2 | |
| Os | 1 | |
| Os | 6 | |
| Os | 6 | |
| Os | 3 |
SAINT Exploits
| Description | Link |
|---|---|
| Internet Explorer iepeers.dll use-after-free vulnerability | More info here |
ExploitDB Exploits
| id | Description |
|---|---|
| 2010-12-14 | Internet Explorer DHTML Behaviors Use After Free |
| 2010-03-10 | Microsoft Internet Explorer iepeers.dll Use-After-Free Exploit (meta) |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 62810 | Microsoft IE iepeers.dll Use-After-Free Arbitrary Code Execution |
Metasploit Database
| id | Description |
|---|---|
| 2010-03-09 | Internet Explorer DHTML Behaviors Use After Free |
Alert History
| Date | Informations |
|---|---|
| 2013-05-11 00:57:20 |
|

VU#744549
(Critical)









