vendor:
Microsoft Internet Explorer
by:
Gjoko 'LiquidWorm' Krstic
N/A
CVSS
N/A
Null Pointer Dereference
CWE
Product Name: Microsoft Internet Explorer
Affected Version From: 11.345.17134.0
Affected Version To: 11.0.9600.17843
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Microsoft Windows 10 (EN) (64bit), Microsoft Windows 7 SP1 (EN) (32/64bit)
2018
Microsoft Internet Explorer 11 – Null Pointer Difference
The crash is caused due to a NULL pointer dereference access violation inside the 'Tree::Notify_InvalidateDisplay' function while parsing malformed DOM elements. The issue was discovered using the Domato fuzzer.