vendor:
Internet Explorer
by:
Marcin Ressel
7.5
CVSS
HIGH
Use After Free
Not mentioned
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer version 11.0.9600.18482
Affected Version To: Not mentioned
Patch Exists: NO
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Windows 7 (x64)
2016
Internet Explorer 11 Use After Free
This exploit allows an attacker to execute arbitrary code in the context of the user running Internet Explorer. The vulnerability occurs due to a use-after-free condition in the MSHTML component of Internet Explorer. By manipulating memory objects, an attacker can corrupt the program's memory and execute malicious code. This exploit has been tested on Windows 7 (x64) with Internet Explorer version 11.0.9600.18482.
Mitigation:
Update Internet Explorer to the latest version or switch to a different web browser.