First published: Thu Mar 25 2010(Updated: )
Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =8.0.6001 | |
Microsoft Windows 7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1117 has a high severity rating due to the potential for remote attackers to exploit the vulnerability to discover critical system information.
To mitigate CVE-2010-1117, it is recommended to update Internet Explorer to the latest version or apply the latest security patches provided by Microsoft.
CVE-2010-1117 may allow attackers to discover the base address of Windows .dll files, potentially leading to further exploits.
CVE-2010-1117 specifically affects Internet Explorer version 8.0.6001 on Microsoft Windows 7.
CVE-2010-1117 does not affect Windows 7 in its entirety; it is specifically tied to the Internet Explorer 8 browser on that operating system.