U.S. Flag Official website of the Department of Homeland Security
TLP:WHITE

Microsoft Internet Explorer 8 use-after-free Vulnerability

Original release date: January 07, 2011 | Last revised: October 23, 2012

US-CERT is aware of a vulnerability affecting Microsoft Internet Explorer 8. This vulnerability is due to improper handling of circular memory references. Exploitation of this vulnerability may allow an attacker to execute arbitrary code in the context of the user or cause a denial-of-service condition.

At this time, the vendor has not released a fix or a workaround to address this vulnerability. Users and administrators are encouraged to consider implementing the mitigations provided in Microsoft's Enhanced Mitigation Experience Toolkit (EMET). These mitigations will not rectify the vulnerability but will make exploitation of the vulnerability more difficult.

Additional information can be found in US-CERT Vulnerability Note VU#427980. US-CERT will provide updates as further details become available.

This product is provided subject to this Notification and this Privacy & Use policy.

Was this document helpful?  Yes  |  Somewhat  |  No

Back to Top