Microsoft Internet Explorer DOM CAnchorElement Use After Free

Strike ID:
E13-3rr01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1080
Year:
2013

Description

This strike exploits a use after free vulnerability in Internet Explorer. The vulnerability in failure to properly delete CAnchorElement objects from the DOM. By enticing a user to view a malicious page a remote attacker could execute arbitrary code on the affected system with the priviledges of the user.

CVE

Bid