First published: Wed Oct 12 2011(Updated: )
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Internet Explorer | =7 | |
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp2 | |
Internet Explorer | =8 | |
Microsoft Windows 7 | ||
Microsoft Windows Server 2008 Itanium | =r2 | |
Microsoft Windows Server 2008 Itanium | =r2-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1996 is classified as a critical vulnerability, potentially allowing remote code execution.
To mitigate CVE-2011-1996, users should update their Internet Explorer to the latest version as recommended by Microsoft.
CVE-2011-1996 affects Microsoft Internet Explorer versions 6, 7, and 8.
Yes, CVE-2011-1996 can be exploited by remote attackers through specially crafted web content.
CVE-2011-1996 primarily affects computers running Windows operating systems with Internet Explorer 6, 7, or 8 installed.