First published: Wed Mar 31 2010(Updated: )
Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =7 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | ||
Microsoft Windows Vista | ||
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows Vista | =sp2 | |
Internet Explorer | =6 | |
Microsoft Windows Server 2003 | =sp2 | |
Internet Explorer | =6-sp1 | |
Microsoft Windows 2000 | =sp4 | |
All of | ||
=7 | ||
Any of | ||
=sp2 | ||
=sp2 | ||
=sp2 | ||
=sp3 | ||
=sp2 | ||
All of | ||
=7 | ||
Any of | ||
=sp2 | ||
=sp2 | ||
=sp2 | ||
=sp1 | ||
=sp2 | ||
All of | ||
=6 | ||
Any of | ||
=sp2 | ||
=sp2 | ||
=sp2 | ||
=sp2 | ||
=sp3 | ||
=sp2 | ||
All of | ||
=6-sp1 | ||
=sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0267 has a critical severity level due to its potential for remote code execution.
To fix CVE-2010-0267, update Microsoft Internet Explorer to the latest version or apply the security patches provided by Microsoft.
CVE-2010-0267 affects Microsoft Internet Explorer versions 6, 6 SP1, and 7 on various Windows operating systems.
Exploitation of CVE-2010-0267 may allow attackers to execute arbitrary code on the affected system, potentially compromising the security.
A potential workaround for CVE-2010-0267 includes disabling Active Scripting in Internet Explorer until a patch can be applied.