imPC@ndo IT

Tracker / CVE-2009-1920

CVE-2009-1920

High 9.3

The JScript scripting engine 5.1, 5.6, 5.7, and 5.8 in JScript.dll in Microsoft Windows, as used in Internet Explorer, does not properly load decoded scripts into memory before execution, which allows remote attackers to execute arbitrary code via a crafted web site that triggers memory corruption, aka "JScript Remote Code Execution Vulnerability."

Affected products and versions

microsoft windows_2000
microsoft windows_server_2003
microsoft windows_server_2008
microsoft windows_vista
microsoft windows_xp

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References