vendor:
Internet Explorer
by:
Unknown
7.5
CVSS
HIGH
Memory Corruption
Unknown
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer Version 11.576.14393.0
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Windows 10 64-bit
Unknown
Memory Corruption Vulnerability in Internet Explorer
There is a memory corruption vulnerability in Internet Explorer. The crash happens in CStyleSheetArray::BuildListOfMatchedRules while attempting to read memory outside of the bounds of the object pointed by eax. If that read is successful and attacker-controlled address is read into edi, this down the line leads to a write at the attacker controlled address in CStyleSheetArray::BuildListOfProbableRules. Thus it might be possible to turn the issue into code execution.
Mitigation:
Unknown