Oval Definition:
oval:org.mitre.oval:def:14781
Revision Date
:
2014-08-18
Version
:
46
Title
:
VML Remote Code Execution Vulnerability
Description
:
Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Remote Code Execution Vulnerability."
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2012-0155
Platform(s)
:
Microsoft Windows 7
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Product(s)
:
Microsoft Internet Explorer 9
Definition Synopsis
Vista x86/x64, Windows 7 x86/x64, Server 2008 x86/x64, Server 2008 R2 x64/ia64, Server 2008 R2 x64/ia64
Microsoft Windows Vista (32-bit) is installed
OR
Microsoft Windows Vista x64 Edition is installed
OR
Microsoft Windows 7 (32-bit) is installed
OR
Microsoft Windows 7 x64 Edition is installed
OR
Microsoft Windows Server 2008 (32-bit) is installed
OR
Microsoft Windows Server 2008 (64-bit) is installed
OR
Microsoft Windows Server 2008 R2 x64 Edition is installed
OR
Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
AND
Microsoft Internet Explorer 9 is installed
AND
GDR or LDR Service branch
Mshtml.dll version is less than 9.0.8112.16441
OR
LDR
Mshtml.dll version is greater than or equal to 9.0.8112.20000
AND
Mshtml.dll version is less than 9.0.8112.20546
BACK