vendor:
Internet Explorer
by:
Anonymous
7,5
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: Internet Explorer
Affected Version From: IE 11.0.9600.18617
Affected Version To: IE 11.0.40
Patch Exists: Yes
Related CWE: N/A
CPE: a:microsoft:internet_explorer:11.0.40
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 64-bit
2020
Memory Corruption Issue in IE
There is a memory corruption issue in IE that can be triggered with svg <use> element. The bug was confirmed on IE Version 11.0.9600.18617 (Update Version 11.0.40) running on Windows 7 64-bit. The PoC code is provided in the text. The crash log when the PoC is ran on 64-bit IE in the single process mode (TabProcGrowth=0) is also provided.
Mitigation:
Update to the latest version of IE and ensure that all security patches are applied.