Microsoft Internet Explorer DOMNodeRemoved Use After Free Condition

Strike ID:
E13-3tz01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2013

Description

This strike exploits a use after free vulnerability in Microsoft Internet Explorer. If an element is removed such as in this case with removeNode and then later used in the event handler for DOMNodeRemoved, a use-after-free condition will occur when trying to call this object because it has been deleted.

CVE

Bid