vendor:
Internet Explorer
by:
Kingcope
9.3
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: Internet Explorer
Affected Version From: 7.0.5730.13
Affected Version To: 7.0.5730.13
Patch Exists: YES
Related CWE: CVE-2009-0075
CPE: a:microsoft:internet_explorer:7.0.5730.13
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=35630, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/browser/ms09_002_memory_corruption, https://www.infosecmatter.com/nessus-plugin-library/?id=58325, https://www.infosecmatter.com/nessus-plugin-library/?id=63402, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/nessus-plugin-library/?id=108808, https://www.infosecmatter.com/nessus-plugin-library/?id=53617
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Microsoft Internet Explorer 7.0.5730.13 – ‘removeChild()’ Remote Code Execution
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the removeChild() method. By passing an object to the removeChild() method, an attacker can cause a NULL pointer dereference resulting in a crash.
Mitigation:
Upgrade to Internet Explorer 8.0 or later.