vendor:
Internet Explorer
by:
Marcin Ressel
7.5
CVSS
HIGH
Use After Free
416
CWE
Product Name: Internet Explorer
Affected Version From: IE11
Affected Version To: IE11 (latest)
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 x64, Windows 7 x64
2016
MSHTML!CMarkupPointer::UnEmbed Use After Free
This exploit targets a vulnerability in the MSHTML!CMarkupPointer::UnEmbed function. It allows an attacker to access memory that has already been freed, potentially leading to arbitrary code execution or a denial of service. The vulnerability was tested on IE11 on Windows 10 x64 and Windows 7 x64. The exploit triggers an access violation exception with the code c0000005.
Mitigation:
Apply the latest security updates and patches provided by Microsoft.