PT-2009-4027 · Microsoft · Vista+5

·

CVE-2009-1530

·

Publicado

2009-06-10

·

Atualizado

2023-12-07

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Explorer 7 for Windows XP SP2 and SP3 Microsoft Internet Explorer 7 for Server 2003 SP2 Microsoft Internet Explorer 7 for Vista Gold, SP1, and SP2 Microsoft Internet Explorer 7 for Server 2008 SP2
Description: A use-after-free issue allows remote attackers to execute arbitrary code by repeatedly adding HTML document nodes and calling event handlers, which triggers an access of an object that was not properly initialized or is deleted. This could allow an attacker to gain the same user rights as the logged-on user, potentially taking complete control of an affected system if the user has administrative rights.
Recommendations: For Microsoft Internet Explorer 7 on all affected platforms, update to a version that addresses this issue to prevent exploitation. As a temporary workaround, consider restricting access to specially crafted Web pages that could trigger the vulnerability until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1530

Produtos afetados

Internet Explorer
Internet Explorer 7
Server 2003
Server 2008
Vista
Windows Xp