Vulnerability record · CVE-2011-1996 · published 12 October 2011
CVE-2011-1996: Internet Explorer use-after-free in option element handling allows remote code execution
Microsoft · Internet Explorer
Microsoft Internet Explorer 6 through 8 fails to properly handle objects in memory, allowing a remote attacker to execute arbitrary code by accessing a deleted object. The flaw is a use-after-free in option element handling, and successful exploitation gives the attacker the same privileges as the logged-on user.
Description
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe CVSS base score is 9.3 (high severity) and EPSS is above the 99th percentile, but the lack of KEV listing and the age of the affected software reduce immediate urgency for patched environments.
What it is
Microsoft Internet Explorer 6 through 8 fails to properly handle objects in memory, allowing a remote attacker to execute arbitrary code by accessing a deleted object. The flaw is a use-after-free in option element handling, and successful exploitation gives the attacker the same privileges as the logged-on user.
Impact
An attacker can execute arbitrary code in the context of the victim's browser session, potentially leading to full system compromise if the user has administrative rights.
Attack surface
The vulnerability is reached over the network via a crafted web page viewed in Internet Explorer 6, 7, or 8. No authentication is required, but user interaction is needed to visit the malicious page or open a malicious link.
Exploitation
The record does not list this CVE in CISA KEV and provides no exploit references, but EPSS indicates a high probability of exploitation activity (0.588, 99th percentile).
What to do
- Apply the patch in Microsoft Security Bulletin MS11-081 immediately.
- Upgrade to a supported version of Internet Explorer or a modern browser.
- Disable or restrict the use of Internet Explorer 6, 7, and 8 where possible.
- Enforce least privilege so users do not browse with administrative rights.
Detection
- Monitor for crashes or unexpected process terminations in iexplore.exe.
- Look for suspicious child processes spawned by iexplore.exe.
- Review web proxy or DNS logs for known malicious domains associated with this vulnerability.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-081 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12896 | Third Party Advisory |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-081 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12896 | Third Party Advisory |
Track CVE-2011-1996 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-1996), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.