{"api_version":"1","generated_at":"2026-07-23T03:24:52+00:00","cve":"CVE-2011-1345","urls":{"html":"https://cve.report/CVE-2011-1345","api":"https://cve.report/api/cve/CVE-2011-1345.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1345","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1345"},"summary":{"title":"CVE-2011-1345","description":"Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka \"Object Management Memory Corruption Vulnerability.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2011-03-10 20:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-018","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-018","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS11-018 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66062","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66062","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA11-102A.html","name":"http://www.us-cert.gov/cas/techalerts/TA11-102A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA11-102A -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/46821","name":"http://www.securityfocus.com/bid/46821","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Internet Explorer Multiple Remote Code Execution Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://twitter.com/aaronportnoy/statuses/45642180118855680","name":"http://twitter.com/aaronportnoy/statuses/45642180118855680","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JavaScript is not available.","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.zdnet.com/blog/security/pwn2own-2011-ie8-on-windows-7-hijacked-with-3-vulnerabilities/8367","name":"http://www.zdnet.com/blog/security/pwn2own-2011-ie8-on-windows-7-hijacked-with-3-vulnerabilities/8367","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Pwn2Own 2011: IE8 on Windows 7 hijacked with 3 vulnerabilities | ZDNet","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011","name":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Threat Intelligence | Digital Vaccine® | ThreatLinQ | Trend Micro","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://twitter.com/msftsecresponse/statuses/45646985998516224","name":"http://twitter.com/msftsecresponse/statuses/45646985998516224","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Response na Twitterze: \"We are on the ground at CanSecWest and our top security researchers are already investigating the IE exploit used in the pwn2own contest.\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.computerworld.com/s/article/9214002/Safari_IE_hacked_first_at_Pwn2Own","name":"http://www.computerworld.com/s/article/9214002/Safari_IE_hacked_first_at_Pwn2Own","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Safari, IE hacked first at Pwn2Own | Computerworld","mime":"text/html","httpstatus":"200","archivestatus":"403"},{"url":"https://threatpost.com/en_us/blogs/pwn2own-winner-stephen-fewer-031011","name":"https://threatpost.com/en_us/blogs/pwn2own-winner-stephen-fewer-031011","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Pwn2Own Winner Stephen Fewer | threatpost","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1025327","name":"http://www.securitytracker.com/id?1025327","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Internet Explorer Bugs Let Remote Users Obtain Potentially Sensitive Information, Execute Arbitrary Code, and Hijack User Clicks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12228","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12228","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1345","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1345","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1345","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1345","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_7","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:21:34.720Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"TA11-102A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA11-102A.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://twitter.com/msftsecresponse/statuses/45646985998516224"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://twitter.com/aaronportnoy/statuses/45642180118855680"},{"name":"1025327","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1025327"},{"name":"MS11-018","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-018"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.computerworld.com/s/article/9214002/Safari_IE_hacked_first_at_Pwn2Own"},{"name":"46821","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/46821"},{"name":"oval:org.mitre.oval:def:12228","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12228"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://threatpost.com/en_us/blogs/pwn2own-winner-stephen-fewer-031011"},{"name":"ms-ie-unspec-code-exec(66062)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66062"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zdnet.com/blog/security/pwn2own-2011-ie8-on-windows-7-hijacked-with-3-vulnerabilities/8367"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-03-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka \"Object Management Memory Corruption Vulnerability.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"TA11-102A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA11-102A.html"},{"tags":["x_refsource_MISC"],"url":"http://twitter.com/msftsecresponse/statuses/45646985998516224"},{"tags":["x_refsource_MISC"],"url":"http://twitter.com/aaronportnoy/statuses/45642180118855680"},{"name":"1025327","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1025327"},{"name":"MS11-018","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-018"},{"tags":["x_refsource_MISC"],"url":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011"},{"tags":["x_refsource_MISC"],"url":"http://www.computerworld.com/s/article/9214002/Safari_IE_hacked_first_at_Pwn2Own"},{"name":"46821","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/46821"},{"name":"oval:org.mitre.oval:def:12228","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12228"},{"tags":["x_refsource_MISC"],"url":"https://threatpost.com/en_us/blogs/pwn2own-winner-stephen-fewer-031011"},{"name":"ms-ie-unspec-code-exec(66062)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66062"},{"tags":["x_refsource_MISC"],"url":"http://www.zdnet.com/blog/security/pwn2own-2011-ie8-on-windows-7-hijacked-with-3-vulnerabilities/8367"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-1345","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka \"Object Management Memory Corruption Vulnerability.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"TA11-102A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA11-102A.html"},{"name":"http://twitter.com/msftsecresponse/statuses/45646985998516224","refsource":"MISC","url":"http://twitter.com/msftsecresponse/statuses/45646985998516224"},{"name":"http://twitter.com/aaronportnoy/statuses/45642180118855680","refsource":"MISC","url":"http://twitter.com/aaronportnoy/statuses/45642180118855680"},{"name":"1025327","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1025327"},{"name":"MS11-018","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-018"},{"name":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011","refsource":"MISC","url":"http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011"},{"name":"http://www.computerworld.com/s/article/9214002/Safari_IE_hacked_first_at_Pwn2Own","refsource":"MISC","url":"http://www.computerworld.com/s/article/9214002/Safari_IE_hacked_first_at_Pwn2Own"},{"name":"46821","refsource":"BID","url":"http://www.securityfocus.com/bid/46821"},{"name":"oval:org.mitre.oval:def:12228","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12228"},{"name":"https://threatpost.com/en_us/blogs/pwn2own-winner-stephen-fewer-031011","refsource":"MISC","url":"https://threatpost.com/en_us/blogs/pwn2own-winner-stephen-fewer-031011"},{"name":"ms-ie-unspec-code-exec(66062)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66062"},{"name":"http://www.zdnet.com/blog/security/pwn2own-2011-ie8-on-windows-7-hijacked-with-3-vulnerabilities/8367","refsource":"MISC","url":"http://www.zdnet.com/blog/security/pwn2own-2011-ie8-on-windows-7-hijacked-with-3-vulnerabilities/8367"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-1345","datePublished":"2011-03-10T20:00:00.000Z","dateReserved":"2011-03-10T00:00:00.000Z","dateUpdated":"2024-08-06T22:21:34.720Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-03-10 20:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*","matchCriteriaId":"A52E757F-9B41-43B4-9D67-3FEDACA71283"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:*","matchCriteriaId":"D56B932B-9593-44E2-B610-E4EB2143EB21"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1345","Ordinal":"1","Title":"CVE-2011-1345","CVE":"CVE-2011-1345","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1345","Ordinal":"1","NoteData":"Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka \"Object Management Memory Corruption Vulnerability.\"","Type":"Description","Title":"CVE-2011-1345"},{"CveYear":"2011","CveId":"1345","Ordinal":"2","NoteData":"2011-03-10","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"1345","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}