Oval Definition:oval:org.mitre.oval:def:12228
Revision Date:2014-08-18Version:50
Title:Object Management Memory Corruption Vulnerability
Description:Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka "Object Management Memory Corruption Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2011-1345
Platform(s):Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Internet Explorer 6
Microsoft Internet Explorer 7
Microsoft Internet Explorer 8
Definition Synopsis
  • Internet Explorer 6 on XP x86
  • Microsoft Windows XP (32-bit) is installed
  • AND Microsoft Internet Explorer 6 is installed
  • AND Mshtml.dll version is less than 6.0.2900.6082
  • OR Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64
  • XP x64, Server 2003 x86/x64/ia64
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • OR Microsoft Windows Server 2003 (ia64) Gold is installed
  • AND Microsoft Internet Explorer 6 is installed
  • AND Mshtml.dll version is less than 6.0.3790.4835
  • OR Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64
  • XP x86/x64, Server 2003 x86/x64/ia64
  • Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • OR Microsoft Windows Server 2003 (ia64) Gold is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND GDR or QFE Service branch
  • Mshtml.dll version is less than 7.0.6000.17097
  • OR QFE
  • Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.21299
  • OR Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64
  • Vista x86/x64, Server 2008 x86/x64/ia64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND GDR or LDR Service branch
  • Mshtml.dll version is less than 7.0.6001.18602
  • OR LDR
  • Mshtml.dll version is greater than 7.0.6001.20000
  • AND Mshtml.dll version is less than 7.0.6001.22857
  • OR Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64
  • Vista x86/x64, Server 2008 x86/x64/ia64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND GDR or LDR Service branch
  • Mshtml.dll version is less than 7.0.6002.18407
  • OR LDR
  • Mshtml.dll version is greater than 7.0.6002.22000
  • AND Mshtml.dll version is less than 7.0.6002.22592
  • OR Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64
  • XP x64,XP x86, Server 2003 x86/x64/ia64
  • Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND Microsoft Internet Explorer 8 is installed
  • AND GDR or QFE Service branch
  • Mshtml.dll version is less than 8.0.6001.19046
  • OR QFE
  • Mshtml.dll version is greater than 8.0.6001.22000
  • AND Mshtml.dll version is less than 8.0.6001.23141
  • OR Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64
  • Vista x86/x64, all Server 2008 x86/x64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • AND Microsoft Internet Explorer 8 is installed
  • AND GDR or LDR Service branch
  • Mshtml.dll version is less than 8.0.6001.19048
  • OR LDR
  • Mshtml.dll version is greater than 8.0.6001.22000
  • AND Mshtml.dll version is less than 8.0.6001.23143
  • OR Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64
  • Windows 7 x86/x64, Server 2008 R2 x64/ia64
  • Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
  • AND Microsoft Internet Explorer 8 is installed
  • AND GDR or LDR Service branch
  • Mshtml.dll version is less than 8.0.7600.16766
  • OR LDR
  • Mshtml.dll version is greater than or equal 8.0.7600.20000
  • AND Mshtml.dll version is less than 8.0.7600.20908
  • OR Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64
  • Windows 7 x86/x64, Server 2008 R2 x64/ia64
  • Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
  • AND Microsoft Internet Explorer 8 is installed
  • AND GDR or LDR Service branch
  • Mshtml.dll version is less than 8.0.7601.17573
  • OR LDR
  • Mshtml.dll version is greater than or equal 8.0.7601.20000
  • AND Mshtml.dll version is less than 8.0.7601.21676
  • BACK