iDefense Security Advisory 10.11.11 – Internet Explorer

0
32

iDefense Security Advisory 10.11.11 – Remote exploitation of a memory corruption vulnerability in Microsoft Corp.’s Internet Explorer could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs when a Javascript event handler such as « onload » is set to a Javascript object’s attributes or childNodes collection. A event object is created and this object’s memory is later freed; however, a reference to the object remains. When the reference is later used to access the event object, this now-invalid memory is treated as a valid object. The corrupt object’s vtable is used to make an indirect function call. This may result in the execution of arbitrary code. Microsoft Internet Explorer 6 is vulnerable.

Source: iDefense Security Advisory 10.11.11 – Internet Explorer