vendor:
Internet Explorer
by:
GradiusX & b33f
N/A
CVSS
N/A
This exploit allows remote code execution through OLE Automation Array in pre-IE11 versions of Internet Explorer. The exploit was originally created by yuange and can be found on http://www.exploit-db.com/exploits/35229/. The rework of the exploit was done by GradiusX and b33f. The exploit uses the Veil-Framework and powershell/shellcode_inject/virtual shellcode. More information on how to use the […]
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer versions prior to IE11
Affected Version To: Internet Explorer versions prior to IE11
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
OLE Automation Array Remote Code Execution => Pre IE11
This exploit allows remote code execution through OLE Automation Array in pre-IE11 versions of Internet Explorer. The exploit was originally created by yuange and can be found on http://www.exploit-db.com/exploits/35229/. The rework of the exploit was done by GradiusX and b33f. The exploit uses the Veil-Framework and powershell/shellcode_inject/virtual shellcode. More information on how to use the exploit can be found on http://www.fuzzysecurity.com/exploits/21.html.
Mitigation:
Update to a version of Internet Explorer that is IE11 or later. Alternatively, use a different web browser.