CVE-2009-2531: Code Injection
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2531?
The severity of CVE-2009-2531 is classified as critical due to the potential for remote code execution.
How do I fix CVE-2009-2531?
To fix CVE-2009-2531, apply the security updates provided by Microsoft for the affected versions of Internet Explorer.
What versions of Internet Explorer are affected by CVE-2009-2531?
CVE-2009-2531 affects Internet Explorer versions 5.01 sp4, 6, 6 sp1, 7, and 8.
What kind of attacks can exploit CVE-2009-2531?
CVE-2009-2531 can be exploited by attackers to execute arbitrary code via specially crafted webpages.
Is there a workaround for CVE-2009-2531 if I can't immediately install the patch?
A temporary workaround for CVE-2009-2531 includes disabling Active Scripting in Internet Explorer until a patch can be applied.