CVE-2009-3672 is a critical memory corruption vulnerability affecting Microsoft Internet Explorer 6 and 7 across various Windows operating systems, including Windows XP, Vista, and Server editions. This flaw allows remote attackers to execute arbitrary code by manipulating uninitialized or deleted objects in memory, specifically through the getElementsByTagName method with the STYLE tag and subsequent modification of the outerHTML property. With a CVSS score of 9.3 (critical) and an EPSS score indicating high exploitability, successful exploitation can lead to complete compromise of confidentiality, integrity, and availability. Exploit code, including a Metasploit module, is publicly available, though there is no indication of active exploitation in the wild or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.