Summary
This host is missing a critical security update according to Microsoft Bulletin MS11-052.
Impact
Successful exploitation could allow remote attackers to execute arbitrary code in the context of the application.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://www.microsoft.com/technet/security/bulletin/MS11-052.mspx
Insight
The flaw is caused when Internet Explorer attempts to access an object that has not been initialised or has been deleted causing memory corruption.
Affected
Microsoft Internet Explorer version 6.x/7.x/8.x
References
Severity
Classification
-
CVE CVE-2011-1266 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft .NET Framework Authentication Bypass and Spoofing Vulnerabilities (2836440)
- Internet Explorer Vector Markup Language Remote Code Execution Vulnerability (2544521)
- Cumulative Security Update for Internet Explorer (961260)
- Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (959426)
- Microsoft .NET Common Language Runtime Code Execution Vulnerability (974378)