CVE-2011-1345 is a critical memory corruption vulnerability affecting Microsoft Internet Explorer versions 6, 7, and 8, specifically impacting Windows 7 users. This flaw allows remote attackers to execute arbitrary code by manipulating objects in memory that are either uninitialized or deleted. With a CVSS score of 9.3, this vulnerability is highly severe, requiring medium attack complexity but granting full confidentiality, integrity, and availability compromise. While there is no readily available exploit code in common frameworks like Metasploit or ExploitDB, it was famously demonstrated as part of a Pwn2Own chain, indicating its exploitability. Although not currently on the CISA KEV catalog, its high FAUCET Risk Score and mention in community discussions and media coverage, including a Krebs on Security article, highlight its historical significance and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.