written by h4ckmp
http://t.qq.com/h4ckmp
欢迎讨论各种漏洞问题.
漏洞信息
Internet Explorer在打开攻击页面时,CMshtmlEd对象被删除并释放,且释放后的内存被重用,导致Use-After-Free.
受影响系统:
Microsoft Internet Explorer 9.x
Microsoft Internet Explorer 8.x
Microsoft Internet Explorer 7.x 发布时间:
2012-09-17 漏洞来源信息:
http://eromang.zataz.com/2012/09/16/zero-day-season-is-really-not-over-yet/ 漏洞类型:
Use-After-Free