CVE-2008-0077Use After Free in Microsoft Internet Explorer

CWE-416Use After Free3 documents3 sources
Severity
8.8HIGHNVD
EPSS
62.3%
top 1.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 12
Latest updateMay 1

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka "Property Memory Corruption Vulnerability."

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-mf54-6363-29h5: Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning mal2022-05-01

📐Framework References

1
CWE
Use After Free
CVE-2008-0077 — Use After Free in Microsoft | cvebase