Microsoft Internet Explorer Layout Handling Use After Free Remote Memory Corruption Vulnerability
BID:47190
Info
Microsoft Internet Explorer Layout Handling Use After Free Remote Memory Corruption Vulnerability
| Bugtraq ID: | 47190 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-0094 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2011 12:00AM |
| Updated: | Apr 15 2011 02:54PM |
| Credit: | An anonymous researcher working with VeriSign iDefense and Mitre |
| Vulnerable: |
Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 SP2 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.2 SP2 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Layout Handling Use After Free Remote Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a remote use-after-free memory-corruption vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the application. Failed exploit attempts will result in denial-of-service conditions.
Microsoft Internet Explorer is prone to a remote use-after-free memory-corruption vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the application. Failed exploit attempts will result in denial-of-service conditions.
Exploit / POC
Microsoft Internet Explorer Layout Handling Use After Free Remote Memory Corruption Vulnerability
Reports indicate that this issue is being exploited in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Reports indicate that this issue is being exploited in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Internet Explorer Layout Handling Use After Free Remote Memory Corruption Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Internet Explorer 7.0
Microsoft Internet Explorer 6.0
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Internet Explorer 7.0
-
Microsoft Windows6.0-KB2497640-x64.msu
http://www.microsoft.com/downloads/details.aspx?FamilyID=79f52733-44e4 -47b6-86ca-1395a095b4e7 -
Microsoft IE7-WindowsServer2003.WindowsXP-KB2497640-x64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=ed88f183-dd06 -46f6-ae8a-a594a752f248 -
Microsoft IE7-WindowsServer2003-KB2497640-ia64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=f1abfb48-3c8a -4b2d-b739-cc61628b387d -
Microsoft Windows6.0-KB2497640-x86.msu
http://www.microsoft.com/downloads/details.aspx?FamilyID=00c3c176-feff -4022-ac4c-2d4732ca3d78 -
Microsoft Windows6.0-KB2497640-ia64.msu
http://www.microsoft.com/downloads/details.aspx?FamilyID=f6f6f22c-fc7f -4e96-b6b5-be3c1acecf6e -
Microsoft IE7-WindowsXP-KB2497640-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=0b7d0403-8965 -4c62-970c-20b561f66713 -
Microsoft IE7-WindowsServer2003-KB2497640-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=5c464287-3dab -4342-a38d-a12719d3b158
Microsoft Internet Explorer 6.0
-
Microsoft WindowsXP-KB2497640-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=c3a8cec0-f947 -4d4e-a6ae-c7f4f1f311b0 -
Microsoft WindowsServer2003-KB2497640-ia64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=8afe86fc-58b4 -4a95-b047-c09138fa4f5e -
Microsoft WindowsServer2003.WindowsXP-KB2497640-x64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=986f07ae-0fdc -4be2-8a74-5eb56d4300ef -
Microsoft WindowsServer2003-KB2497640-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=b902c58a-9e2f -4352-8d2f-fffda5344598
References
Microsoft Internet Explorer Layout Handling Use After Free Remote Memory Corruption Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)
- Microsoft Internet Explorer Use-After-Free Memory Corruption Vulnerability (iDefense)
- VUPEN Security Research - Microsoft Internet Explorer Layouts Use-after-free Vul ("VUPEN Security Research"
) - ASA-2011-094 MS11-018 Cumulative Security Update for Internet Explorer (2497640) (Avaya)
- Microsoft Security Bulletin MS11-018 (Microsoft)