CVE-2011-1996: Critical severity internet explorer vulnerability
Published Oct 12, 2011
·Updated
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."
Affected Software
14 affected components
Microsoft Internet Explorer=6
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
Microsoft Internet Explorer=7
Microsoft Windows Server 2008
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp1
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp2
Microsoft Internet Explorer=8
Microsoft Windows 7
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2-sp1
Remediation
Event History
Oct 12, 2011
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
02:52 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-1996?
CVE-2011-1996 is classified as a critical vulnerability, potentially allowing remote code execution.
2
How do I fix CVE-2011-1996?
To mitigate CVE-2011-1996, users should update their Internet Explorer to the latest version as recommended by Microsoft.
3
Which versions of Internet Explorer are affected by CVE-2011-1996?
CVE-2011-1996 affects Microsoft Internet Explorer versions 6, 7, and 8.
4
Can CVE-2011-1996 be exploited remotely?
Yes, CVE-2011-1996 can be exploited by remote attackers through specially crafted web content.
5
What systems are vulnerable to CVE-2011-1996?
CVE-2011-1996 primarily affects computers running Windows operating systems with Internet Explorer 6, 7, or 8 installed.