vendor:
Internet Explorer
by:
Drozdova Liudmila
7,6
CVSS
HIGH
Use-after-free and memory corruption
416
CWE
Product Name: Internet Explorer
Affected Version From: 9
Affected Version To: 10
Patch Exists: NO
Related CWE: unknown
CPE: a:microsoft:internet_explorer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1 x86 IE 9,10
2014
MS14-035 Internet Explorer CFormElement Use-after-free and memory corruption POC (no crash! see trace)
MSHTML!CInput::DoClick contains a use-after-free vulnerability. When the DoClick function is called, the CFormElement object is freed, but the pointer is still used to write to memory. This can lead to memory corruption and potentially arbitrary code execution.
Mitigation:
No known mitigation is available at this time.