First published: Thu Jun 16 2011(Updated: )
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Drag and Drop Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Internet Explorer | =7 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp2 | |
Internet Explorer | =8 | |
Microsoft Windows 7 | ||
Microsoft Windows Server | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1254 has a severity rating of critical due to the potential for remote code execution.
To fix CVE-2011-1254, it is recommended to apply the security updates provided by Microsoft as outlined in the corresponding security bulletin.
CVE-2011-1254 affects Internet Explorer versions 6, 7, and 8.
CVE-2011-1254 is identified as a memory corruption vulnerability that can lead to arbitrary code execution.
CVE-2011-1254 can affect systems running Internet Explorer 6, 7, or 8, which may include older versions of Windows.