CVE-2008-1085: Code Injection
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that does not have a registered handler.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1085?
CVE-2008-1085 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2008-1085?
To fix CVE-2008-1085, update Microsoft Internet Explorer to a version that addresses this vulnerability.
Which versions of Internet Explorer are affected by CVE-2008-1085?
CVE-2008-1085 affects Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7.
What kind of attack does CVE-2008-1085 enable?
CVE-2008-1085 allows remote attackers to execute arbitrary code via crafted data streams.
Is there a workaround for CVE-2008-1085?
While there is no specific workaround for CVE-2008-1085, users are advised to avoid untrusted content and consider transitioning away from affected versions.