vendor:
Internet Explorer
by:
Project Zero
8,8
CVSS
HIGH
Use-After-Free
416
CWE
Product Name: Internet Explorer
Affected Version From: 11.0.9600.18537
Affected Version To: 11.0.38
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:internet_explorer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2018
Use-After-Free Vulnerability in Internet Explorer 11.0.9600.18537
A use-after-free vulnerability exists in Internet Explorer 11.0.9600.18537 (update version 11.0.38) which can lead to info leak / memory disclosure. The root cause of the bug is a use-after-free on the textarea text value, which can be seen if a PoC is run with Page Heap enabled.
Mitigation:
Update to the latest version of Internet Explorer.