First published: Wed Oct 12 2011(Updated: )
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "OLEAuto32.dll Remote Code Execution Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Internet Explorer | =7 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp2 | |
Internet Explorer | =8 | |
Microsoft Windows 7 | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server | =r2-sp1 | |
Internet Explorer | =9 | |
Microsoft Windows 7 | =sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1995 has a critical severity rating as it allows remote code execution.
To fix CVE-2011-1995, apply the appropriate security updates provided by Microsoft.
CVE-2011-1995 affects Internet Explorer versions 6 through 9.
CVE-2011-1995 is associated with improper memory handling that can lead to remote code execution.
Yes, Windows XP with Internet Explorer versions 6, 7, 8, and 9 is vulnerable to CVE-2011-1995.