CVE-2011-1345
Summary
| CVE | CVE-2011-1345 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-03-10 20:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka "Object Management Memory Corruption Vulnerability." |
Risk And Classification
Primary CVSS: v2.0 9.3 from [email protected]
AV:N/AC:M/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Explorer | 8 | All | All | All |
| Operating System | Microsoft | Windows 7 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Security Bulletin MS11-018 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| US-CERT Technical Cyber Security Alert TA11-102A -- Microsoft Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Microsoft Internet Explorer Multiple Remote Code Execution Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| JavaScript is not available. | af854a3a-2127-422b-91ae-364da2661108 | twitter.com | |
| Pwn2Own 2011: IE8 on Windows 7 hijacked with 3 vulnerabilities | ZDNet | af854a3a-2127-422b-91ae-364da2661108 | www.zdnet.com | |
| Threat Intelligence | Digital Vaccine® | ThreatLinQ | Trend Micro | af854a3a-2127-422b-91ae-364da2661108 | dvlabs.tippingpoint.com | |
| Security Response na Twitterze: "We are on the ground at CanSecWest and our top security researchers are already investigating the IE exploit used in the pwn2own contest." | af854a3a-2127-422b-91ae-364da2661108 | twitter.com | |
| Safari, IE hacked first at Pwn2Own | Computerworld | af854a3a-2127-422b-91ae-364da2661108 | www.computerworld.com | |
| Pwn2Own Winner Stephen Fewer | threatpost | af854a3a-2127-422b-91ae-364da2661108 | threatpost.com | |
| Microsoft Internet Explorer Bugs Let Remote Users Obtain Potentially Sensitive Information, Execute Arbitrary Code, and Hijack User Clicks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.