Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
- Type
- Logic error
- Impact of exploitation
- Remote Code Execution
- User Interaction
- no user interaction is needed
- Attack Vector
- Website with malicious content
- Rating
- Medium
Description
A vulnerability exists in Microsoft Internet Explorer that could allow remote code execution. The vulnerability is in the way Internet Explorer accesses an object that has not been correctly initialized or deleted. The vulnerability can be exploited by creating a specially crafted Web page. When the Web page is viewed, the vulnerability could allow remote code execution.
Recommendations -
The vendor has released an update to address this issue http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx