Microsoft Internet Explorer SLayoutRun Use-After-Free Remote Code Execution Vulnerability
BID:57830
Info
Microsoft Internet Explorer SLayoutRun Use-After-Free Remote Code Execution Vulnerability
| Bugtraq ID: | 57830 |
| Class: | Unknown |
| CVE: |
CVE-2013-0025 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2013 12:00AM |
| Updated: | Mar 19 2015 08:08AM |
| Credit: | Scott Bell of Security-Assessment.com |
| Vulnerable: |
Microsoft Internet Explorer 8 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Conferencing 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer SLayoutRun Use-After-Free Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer version 8 is affected.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer version 8 is affected.
Exploit / POC
Microsoft Internet Explorer SLayoutRun Use-After-Free Remote Code Execution Vulnerability
The following exploit code is available as a module from the Metasploit Framework:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available as a module from the Metasploit Framework:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Internet Explorer SLayoutRun Use-After-Free Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Internet Explorer SLayoutRun Use-After-Free Remote Code Execution Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)