This application requires Javascript for optimal performance.

MS.IE.XSLT.Memory.Corruption.Remote.Code.Execution

Release Date

Aug 10, 2011

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a Memory Corruption vulnerability in Microsoft Internet Explorer.

The vulnerability is a result of the application's failure to sanitize user supplied input. It can allow a remote attacker to execute arbitrary code within the context of the browser or possibly cause a Denial of Service of condition.

Affected Products

Microsoft Internet Explorer 6
Microsoft Internet Explorer 7
Microsoft Internet Explorer 8
Microsoft Internet Explorer 9

Recommended Actions

Apply the patch available from the website.
http://www.microsoft.com/technet/security/Bulletin/11-057.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-1963

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/MS11-057.mspx (MS-ID)
http://www.securityfocus.com/bid/49037 (BugTraq)

Reference: VID-28654