MS.IE.Freed.Object.Acess.Heap.Corruption

Last Updated DateJul 02, 2009
Release DateJun 11, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems
DescriptionThis indicates a possible attack against a heap-corruption vulnerability in Microsoft Internet Explorer.

The vulnerability is due to the software's inability to properly handle accessing uninitialized or deleted objects. Remote attackers may exploit this to execute arbitrary code.
Affected ProductsMicrosoft Internet Explorer 7.0
Other versions may also be infected
Recommended ActionsApply patch, available from the web site:
http://www.microsoft.com/technet/security/Bulletin/ms09-019.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1530
Microsoft Bulletin IDMS09-019   http://www.microsoft.com/technet/security/Bulletin/ms09-019.mspx
Reference: VID-17506