CVE-2011-1995: Critical severity internet explorer vulnerability
Published Oct 12, 2011
·Updated
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "OLEAuto32.dll Remote Code Execution Vulnerability."
Affected Software
16 affected components
Microsoft Internet Explorer=6
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
Microsoft Internet Explorer=7
Microsoft Windows Server 2008
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp1
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp2
Microsoft Internet Explorer=8
Microsoft Windows 7
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2-sp1
Microsoft Internet Explorer=9
Microsoft Windows 7=sp1
Remediation
Event History
Oct 12, 2011
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
02:52 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-1995?
CVE-2011-1995 has a critical severity rating as it allows remote code execution.
2
How do I fix CVE-2011-1995?
To fix CVE-2011-1995, apply the appropriate security updates provided by Microsoft.
3
Which versions of Internet Explorer are affected by CVE-2011-1995?
CVE-2011-1995 affects Internet Explorer versions 6 through 9.
4
What vulnerabilities are associated with CVE-2011-1995?
CVE-2011-1995 is associated with improper memory handling that can lead to remote code execution.
5
Is Windows XP vulnerable to CVE-2011-1995?
Yes, Windows XP with Internet Explorer versions 6, 7, 8, and 9 is vulnerable to CVE-2011-1995.