Lucene search

K
zdiJose A. Vazquez of {http://spa-s3c.blogspot.com}ZDI-11-194
HistoryJun 14, 2011 - 12:00 a.m.

Microsoft Internet Explorer layout-grid-char style Remote Code Execution Vulnerability

2011-06-1400:00:00
Jose A. Vazquez of {http://spa-s3c.blogspot.com}
www.zerodayinitiative.com
20

EPSS

0.973

Percentile

99.9%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Internet Explorer handles unusual values for the layout-grid-char style property. Specific values may result in the destruction of a tree node that is still in use during the rendering of the HTML page. The resulting use-after-free vulnerability can be leveraged to achieve remote code execution.