CVE-2011-1266

Description

The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka VML Memory Corruption Vulnerability.

Risk Information

Base Score
6.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
35.62

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Internet Explorer 6 for Windows XP (KB2544521)Windows
Security Update for Internet Explorer 6 for Windows Server 2003 (KB2544521)Windows
Security Update for Internet Explorer 6 for Windows Server 2003 x64 Edition (KB2544521)Windows
Security Update for Internet Explorer 7 for Windows XP (KB2544521)Windows
Security Update for Internet Explorer 7 for Windows Server 2003 (KB2544521)Windows
Security Update for Internet Explorer 7 for Windows Vista (KB2544521) x86 based systemsWindows
Security Update for Internet Explorer 7 for Windows Vista (KB2544521) x86 based systems for SP2Windows
Security Update for Internet Explorer 7 for Windows Server 2008 (KB2544521) x86 based systemsWindows
Security Update for Internet Explorer 7 for Windows Server 2008 (KB2544521) x86 based systems for SP2Windows
Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2544521)Windows
Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2544521)Windows
Security Update for Internet Explorer 7 for Windows Vista for x64-based Systems (KB2544521)Windows
Security Update for Internet Explorer 7 for Windows Vista for x64-based Systems (KB2544521) for SP2Windows
Security Update for Internet Explorer 7 for Windows Server 2008 x64 Edition (KB2544521)Windows
Security Update for Internet Explorer 7 for Windows Server 2008 x64 Edition (KB2544521) for SP2Windows
Security Update for Internet Explorer 8 for Windows XP (KB2544521)Windows
Security Update for Internet Explorer 8 for Windows Server 2003 (KB2544521)Windows
Security Update for Internet Explorer 8 for Windows Vista (KB2544521) x86 based systemsWindows
Security Update for Internet Explorer 8 for Windows Vista (KB2544521) x86 based systems for SP2Windows
Security Update for Internet Explorer 8 for Windows Server 2008 (KB2544521) x86 based systemsWindows
Security Update for Internet Explorer 8 for Windows Server 2008 (KB2544521) x86 based systems for SP2Windows
Security Update for Internet Explorer 8 for Windows 7 (KB2544521) x86 based systemsWindows
Security Update for Internet Explorer 8 for Windows 7 (KB2544521) x86 based systems for SP1Windows
Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2544521)Windows
Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2544521)Windows
Security Update for Internet Explorer 8 for Windows Vista for x64-based Systems (KB2544521)Windows
Security Update for Internet Explorer 8 for Windows Vista for x64-based Systems (KB2544521) for SP2Windows
Security Update for Internet Explorer 8 for Windows Server 2008 x64 Edition (KB2544521)Windows
Security Update for Internet Explorer 8 for Windows Server 2008 x64 Edition (KB2544521) for SP2Windows
Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2544521)Windows
Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2544521) for SP1Windows
Security Update for Internet Explorer 8 for Windows Server 2008 R2 x64 Edition (KB2544521)Windows
Security Update for Internet Explorer 8 for Windows Server 2008 R2 x64 Edition (KB2544521) for SP1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-10611Security Update for Internet Explorer 6 for Windows XP (KB2544521)
PATCH-10612Security Update for Internet Explorer 6 for Windows Server 2003 (KB2544521)
PATCH-10614Security Update for Internet Explorer 6 for Windows Server 2003 x64 Edition (KB2544521)
PATCH-10615Security Update for Internet Explorer 7 for Windows XP (KB2544521)
PATCH-10616Security Update for Internet Explorer 7 for Windows Server 2003 (KB2544521)
PATCH-10618Security Update for Internet Explorer 7 for Windows Vista (KB2544521)
PATCH-10620Security Update for Internet Explorer 7 for Windows Server 2008 (KB2544521)
PATCH-10621Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2544521)
PATCH-10622Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2544521)
PATCH-10624Security Update for Internet Explorer 7 for Windows Vista for x64-based Systems (KB2544521)
PATCH-10626Security Update for Internet Explorer 7 for Windows Server 2008 x64 Edition (KB2544521)
PATCH-10627Security Update for Internet Explorer 8 for Windows XP (KB2544521)
PATCH-10628Security Update for Internet Explorer 8 for Windows Server 2003 (KB2544521)
PATCH-10630Security Update for Internet Explorer 8 for Windows Vista (KB2544521)
PATCH-10632Security Update for Internet Explorer 8 for Windows Server 2008 (KB2544521)
PATCH-10633Security Update for Internet Explorer 8 for Windows 7 (KB2544521)
PATCH-10634Security Update for Internet Explorer 8 for Windows 7 (KB2544521)
PATCH-10635Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2544521)
PATCH-10636Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2544521)
PATCH-10638Security Update for Internet Explorer 8 for Windows Vista for x64-based Systems (KB2544521)
PATCH-10640Security Update for Internet Explorer 8 for Windows Server 2008 x64 Edition (KB2544521)
PATCH-10641Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2544521)
PATCH-10642Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2544521)
PATCH-10643Security Update for Internet Explorer 8 for Windows Server 2008 R2 x64 Edition (KB2544521)
PATCH-10644Security Update for Internet Explorer 8 for Windows Server 2008 R2 x64 Edition (KB2544521)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234