Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7...
Vulnerability Description
Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-1346
Credits & Attribution
No credits recorded in the NVD database.
References
- http://twitter.com/msftsecresponse/statuses/45646985998516224
- http://twitter.com/aaronportnoy/statuses/45642180118855680
- http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011
- http://www.computerworld.com/s/article/9214002/Safari_IE_hacked_first_at_Pwn2Own
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66063
- http://www.securityfocus.com/bid/46821
- https://threatpost.com/en_us/blogs/pwn2own-winner-stephen-fewer-031011
- http://www.zdnet.com/blog/security/pwn2own-2011-ie8-on-windows-7-hijacked-with-3-vulnerabilities/8367
More from microsoft
View All →Affected Vendor
microsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.