CVE-2011-1255
EXPLOITEDInternet Explorer 6-8 - Use-After-Free in Timed Interactive Multimedia Extensions
Title source: llmExploitation Summary
CVE-2011-1255 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Ciph3r.
AI-analyzed exploit summary This exploit targets a memory corruption vulnerability in Internet Explorer's Timed Interactive Multimedia Extensions (HTML+TIME) to achieve remote code execution, bypassing DEP and ASLR on Windows 7 with IE 8.
Description
The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Time Element Memory Corruption Vulnerability."
Exploits (1)
This exploit targets a memory corruption vulnerability in Internet Explorer's Timed Interactive Multimedia Extensions (HTML+TIME) to achieve remote code execution, bypassing DEP and ASLR on Windows 7 with IE 8.