vendor:
Internet Explorer
by:
Project Zero
7,6
CVSS
HIGH
Use-after-free
416
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 9
Affected Version To: Internet Explorer 11
Patch Exists: YES
Related CWE: CVE-2015-6136
CPE: a:microsoft:internet_explorer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2015
Use-after-free in SVG pattern element
A use-after-free vulnerability exists in the SVG pattern element in Microsoft Internet Explorer. An attacker can exploit this vulnerability by creating a malicious SVG file and convincing the user to open it. This will allow the attacker to execute arbitrary code on the target system.
Mitigation:
Microsoft released a patch to address this vulnerability.