Microsoft Internet Explorer Layouts Use-After-Free

0
41

The VUPEN Vulnerability Research Team discovered a critical vulnerability in Microsoft Internet Explorer. The vulnerability is caused by a use-after-free error in the « CSpliceTreeEngine::InsertSplice() » function within the MSHTML library when handling layouts, which could be exploited by remote attackers to compromise a vulnerable system by tricking a user into visiting a specially crafted web page. Versions 6 and 7 are affected.

Source: Microsoft Internet Explorer Layouts Use-After-Free