CVE-2011-1997: Input Validation
Published Oct 12, 2011
·Updated
Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnLoad Event Remote Code Execution Vulnerability."
Affected Software
6 affected components
Microsoft Internet Explorer=6
Microsoft Windows 2003 Server=sp2
Microsoft Windows 2003 Server=sp2
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
Event History
Oct 12, 2011
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
02:52 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-1997?
CVE-2011-1997 is classified as a critical vulnerability that allows remote attackers to execute arbitrary code.
2
How can I mitigate CVE-2011-1997?
To mitigate CVE-2011-1997, it is recommended to upgrade to a later version of Microsoft Internet Explorer that is not vulnerable.
3
What systems are affected by CVE-2011-1997?
CVE-2011-1997 specifically affects Microsoft Internet Explorer 6.
4
Is there a patch available for CVE-2011-1997?
Yes, Microsoft released a security update to address CVE-2011-1997.
5
What type of attack does CVE-2011-1997 facilitate?
CVE-2011-1997 facilitates remote code execution attacks by exploiting improper memory handling in Internet Explorer.