CVE-2009-1528: Critical severity internet explorer vulnerability
Microsoft Internet Explorer 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly synchronize AJAX requests, which allows allows remote attackers to execute arbitrary code via a large number of concurrent, asynchronous XMLHttpRequest calls, aka "HTML Object Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1528?
CVE-2009-1528 has a high severity rating, indicating a significant risk to affected systems.
Which systems are affected by CVE-2009-1528?
CVE-2009-1528 affects Microsoft Internet Explorer versions 6 and 7 on Windows XP, Server 2003, Vista, and Server 2008.
How do I fix CVE-2009-1528?
To fix CVE-2009-1528, users should upgrade to the latest version of Internet Explorer that is not affected by this vulnerability.
What can attackers do by exploiting CVE-2009-1528?
Exploiting CVE-2009-1528 allows attackers to execute arbitrary code on vulnerable systems through poorly synchronized AJAX requests.
Is there a workaround for CVE-2009-1528?
As a temporary workaround for CVE-2009-1528, users can disable JavaScript execution in Internet Explorer, but this may limit functionality.