CVE-2011-1996

Microsoft Internet Explorer <9 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2011-1996. PoCs published by Metasploit, Ivan Fratric, juan vazquez, sinn3r, including Metasploit module exploits/windows/browser/ms11_081_option.

AI-analyzed exploit summary This Metasploit module exploits a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2011-1996) by manipulating the Option element cache, leading to remote code execution via heap spraying and ROP chains.

Description

Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/24020

This Metasploit module exploits a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2011-1996) by manipulating the Option element cache, leading to remote code execution via heap spraying and ROP chains.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Microsoft Internet Explorer 8 on Windows XP SP3, Vista, or 7
No auth needed
Prerequisites: Victim must visit a malicious webpage · JavaScript must be enabled in the target browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Ivan Fratric, juan vazquez, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms11_081_option.rb

This Metasploit module exploits a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2011-1996) by manipulating the Option element cache, leading to arbitrary code execution. It uses heap spraying and ROP chains tailored for different IE 8 and Windows versions.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Microsoft Internet Explorer 8 on Windows XP SP3, Vista, or 7
No auth needed
Prerequisites: Victim must visit a malicious webpage · JavaScript must be enabled in the target browser
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (2)

Core 2
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-081

Scores

EPSS 0.6046
EPSS Percentile 99.0%

Details

Status published
Products (3)
microsoft/internet_explorer 6
microsoft/internet_explorer 7
microsoft/internet_explorer 8
Published Oct 12, 2011
Tracked Since Feb 18, 2026