Oval Definition:
oval:org.mitre.oval:def:15886
Revision Date
:
2014-08-18
Version
:
46
Title
:
CTreePos use after free vulnerability - MS12-071
Description
:
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka "CTreePos Use After Free Vulnerability."
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2012-1539
Platform(s)
:
Microsoft Windows 7
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Product(s)
:
Microsoft Internet Explorer 9
Definition Synopsis
Microsoft Internet Explorer 9 is installed
AND
Check for OS
Microsoft Windows Vista (32-bit) is installed
OR
Microsoft Windows Vista x64 Edition is installed
OR
Microsoft Windows Server 2008 (32-bit) is installed
OR
Microsoft Windows Server 2008 (64-bit) is installed
OR
Microsoft Windows 7 is installed
OR
Microsoft Windows 7 (32-bit) is installed
OR
Microsoft Windows 7 x64 Edition is installed
OR
Microsoft Windows Server 2008 R2 x64 Edition is installed
AND
Check for LDR/GDR
Check if version of Mshtml.dll is less than 9.0.8112.16455
OR
Check for LDR
Check if version of Mshtml.dll is less than 9.0.8112.20562
AND
Mshtml.dll version is greater than or equal to 9.0.8112.20000
BACK