First published: Fri Sep 18 2009(Updated: )
Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | >=6.0<=6.00.2900.2180 | |
Internet Explorer | >=7.0<=7.0.6000.16711 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3267 has a severity rating that indicates it can lead to a denial of service due to high CPU consumption.
CVE-2009-3267 allows remote attackers to exploit Internet Explorer versions 6 and 7 using an automatically submitted form with a KEYGEN element.
CVE-2009-3267 affects Microsoft Internet Explorer versions 6.0 through 6.0.2900.2180 and 7.0.6000.16711.
Mitigating CVE-2009-3267 involves updating Internet Explorer to the latest version available.
Microsoft has not released a specific patch for CVE-2009-3267, hence upgrading to a non-vulnerable version is the recommended action.