Microsoft Internet Explorer CTreeNode::GetCascadedLang Use-After-Free

Discussion in 'News Aggregator' started by Packet Storm, 13 Aug 2015.

  1. Packet Storm

    Packet Storm Guest

    Microsoft Internet Explorer 11 is prone to a use-after-free vulnerability in the MSHTML!CTreeNode::GetCascadedLang function. The following analysis was performed on Internet Explorer 11 on Windows 8.1 (x64). If an attacker succeeds in bypassing the Memory Protector and Isolated Heap protection mechanisms this vulnerability allows the execution of arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

    Continue reading...
     

Share This Page

Loading...