Vulnerability Name: CVE-2009-0075 (CCN-48309) Assigned: 2009-02-10 Published: 2009-02-10 Updated: 2019-02-27 Summary: Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability." CVSS v3 Severity: 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )7.3 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )7.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-399 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2009-0075 Source: OSVDB Type: Broken Link51839 Source: CCN Type: ASA-2009-053MS09-002 Cumulative Security Update for Internet Explorer (961260) Source: CCN Type: NORTEL BULLETIN ID: 2009009324, Rev 1Nortel Response to Microsoft Security Bulletin MS09-002 - Cumulative Security Update for Internet Explorer Source: CCN Type: Microsoft Security Bulletin MS09-002Cumulative Security Update for Internet Explorer (961260) Source: CCN Type: Microsoft Security Bulletin MS09-014Cumulative Security Update for Internet Explorer (963027) Source: CCN Type: OSVDB ID: 51839Microsoft IE Document Object Handling Memory Corruption Arbitrary Code Execution Source: BID Type: Third Party Advisory, VDB Entry33627 Source: CCN Type: BID-33627Microsoft Internet Explorer Uninitialized Memory Remote Code Execution Vulnerability Source: CERT Type: Third Party Advisory, US Government ResourceTA09-041A Source: VUPEN Type: Vendor AdvisoryADV-2009-0389 Source: MISC Type: Third Party Advisory, VDB Entryhttp://www.zerodayinitiative.com/advisories/ZDI-09-011/ Source: MS Type: Patch, Vendor AdvisoryMS09-002 Source: XF Type: UNKNOWNie-memory-code-execution(48309) Source: OVAL Type: Third Party Advisoryoval:org.mitre.oval:def:6000 Source: EXPLOIT-DB Type: Third Party Advisory, VDB Entry8077 Source: EXPLOIT-DB Type: Third Party Advisory, VDB Entry8079 Source: EXPLOIT-DB Type: Third Party Advisory, VDB Entry8080 Source: EXPLOIT-DB Type: Third Party Advisory, VDB Entry8082 Source: CCN Type: ZDI-09-011Microsoft Internet Explorer CFunctionPointer Memory Corruption Vulnerability Vulnerable Configuration: Configuration 1 :cpe:/a:microsoft:internet_explorer:7:*:*:*:*:*:*:* AND cpe:/o:microsoft:windows_server_2003:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2003:-:sp1:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2003:-:sp1:itanium:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:itanium:* OR cpe:/o:microsoft:windows_vista:-:*:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_vista:-:sp1:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_xp:-:*:professional:*:*:*:x64:* OR cpe:/o:microsoft:windows_xp:-:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows_xp:-:sp2:professional:*:*:*:x64:* OR cpe:/o:microsoft:windows_xp:-:sp3:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x32:* AND cpe:/o:microsoft:windows:2003_server::x64:*:*:*:*:* OR cpe:/o:microsoft:windows:xp:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows:2003_server:sp1:*:*:*:*:*:* OR cpe:/o:microsoft:windows:2003_server:sp1_itanium:*:*:*:*:*:* OR cpe:/o:microsoft:windows_vista:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows:server_2003:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows:server_2003:sp2:itanium:*:*:*:*:* OR cpe:/o:microsoft:windows:server_2003:sp2:x64:*:*:*:*:* OR cpe:/o:microsoft:windows_vista:-:*:x64:*:*:*:*:* OR cpe:/o:microsoft:windows_xp::sp2:x64:*:professional:*:*:* OR cpe:/o:microsoft:windows_vista:-:sp1:*:*:*:*:*:* OR cpe:/o:microsoft:windows_vista:-:sp1:x64:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:itanium:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x64:* OR cpe:/o:microsoft:windows:xp:sp3:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
microsoft internet explorer 7
microsoft windows server 2003 -
microsoft windows server 2003 - sp1
microsoft windows server 2003 - sp1
microsoft windows server 2003 - sp2
microsoft windows server 2008 *
microsoft windows server 2008 -
microsoft windows vista -
microsoft windows vista - sp1
microsoft windows xp -
microsoft windows xp - sp2
microsoft windows xp - sp2
microsoft windows xp - sp3
microsoft ie 7.0
microsoft windows server 2008 -
microsoft windows 2003_server
microsoft windows xp sp2
microsoft windows 2003_server sp1
microsoft windows 2003_server sp1_itanium
microsoft windows vista *
microsoft windows server_2003 sp2
microsoft windows server_2003 sp2
microsoft windows server_2003 sp2
microsoft windows vista -
microsoft windows xp sp2
microsoft windows vista - sp1
microsoft windows vista - sp1
microsoft windows server 2008 -
microsoft windows server 2008 -
microsoft windows xp sp3