CVE-2011-1993: Critical severity internet explorer vulnerability
Published Oct 12, 2011
·Updated
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Scroll Event Remote Code Execution Vulnerability."
Affected Software
16 affected components
Microsoft Internet Explorer=6
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
Microsoft Internet Explorer=7
Microsoft Windows Server 2008
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp1
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp2
Microsoft Internet Explorer=8
Microsoft Windows 7
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2-sp1
Microsoft Internet Explorer=9
Microsoft Windows 7=sp1
Remediation
Event History
Oct 12, 2011
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
02:52 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-1993?
CVE-2011-1993 is rated as critical due to its potential to allow remote code execution.
2
How do I fix CVE-2011-1993?
To fix CVE-2011-1993, users should apply the latest security updates provided by Microsoft.
3
Which versions of Internet Explorer are affected by CVE-2011-1993?
CVE-2011-1993 affects Microsoft Internet Explorer versions 6, 7, 8, and 9.
4
What is the nature of the vulnerability in CVE-2011-1993?
CVE-2011-1993 involves improper handling of objects in memory, allowing access to deleted objects.
5
Can I mitigate CVE-2011-1993 if I cannot apply updates immediately?
While immediate updates are the best course of action, consider using alternative browsers to mitigate exposure to CVE-2011-1993.