VULNERABILITY INTELLIGENCE
CVE-2011-1995
CVSS score9.3 HIGH
EPSS probability28.90%
CISA KEVNot currently listed
Published2011-10-12
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Description
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "OLEAuto32.dll Remote Code Execution Vulnerability."
Weakness classification
- CWE-908: Use of Uninitialized Resource
Primary references
- secure@microsoft.com — Patch, Vendor Advisory
- secure@microsoft.com — Tool Signature
- af854a3a-2127-422b-91ae-364da2661108 — Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Tool Signature