CVE-2009-1140: Infoleak
Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Cross-Domain Information Disclosure Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1140?
CVE-2009-1140 is rated as critical due to its potential to allow remote code execution by exploiting the browser's handling of cached content.
How do I fix CVE-2009-1140?
To resolve CVE-2009-1140, users should install the latest security updates and patches provided by Microsoft for Internet Explorer.
Which versions of Internet Explorer are affected by CVE-2009-1140?
CVE-2009-1140 affects Internet Explorer versions 5.01 SP4, 6 SP1, 6, 7, and several versions across Windows XP, Windows Vista, and Windows Server 2003.
Can CVE-2009-1140 affect Windows Vista?
Yes, CVE-2009-1140 can impact Windows Vista users running Internet Explorer 7, particularly in its earlier service packs.
Is there a workaround for CVE-2009-1140?
While the best solution is to apply the security patch, users can also restrict the execution of scripts or disable caching in Internet Explorer as a temporary workaround.