Exploitation Summary
EIP tracks 2 public exploits for CVE-2011-1996.
PoCs published by Metasploit, Ivan Fratric, juan vazquez, sinn3r, including Metasploit module exploits/windows/browser/ms11_081_option.
AI-analyzed exploit summary This Metasploit module exploits a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2011-1996) by manipulating the Option element cache, leading to remote code execution via heap spraying and ROP chains.
Description
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."
Exploits (2)
This Metasploit module exploits a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2011-1996) by manipulating the Option element cache, leading to remote code execution via heap spraying and ROP chains.
This Metasploit module exploits a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2011-1996) by manipulating the Option element cache, leading to arbitrary code execution. It uses heap spraying and ROP chains tailored for different IE 8 and Windows versions.