First published: Wed Oct 12 2011(Updated: )
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Scroll Event Remote Code Execution Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Internet Explorer | =7 | |
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp2 | |
Internet Explorer | =8 | |
Microsoft Windows 7 | ||
Microsoft Windows Server 2008 Itanium | =r2 | |
Microsoft Windows Server 2008 Itanium | =r2-sp1 | |
Internet Explorer | =9 | |
Microsoft Windows 7 | =sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1993 is rated as critical due to its potential to allow remote code execution.
To fix CVE-2011-1993, users should apply the latest security updates provided by Microsoft.
CVE-2011-1993 affects Microsoft Internet Explorer versions 6, 7, 8, and 9.
CVE-2011-1993 involves improper handling of objects in memory, allowing access to deleted objects.
While immediate updates are the best course of action, consider using alternative browsers to mitigate exposure to CVE-2011-1993.