High severity8.8NVD Advisory· Published Jun 10, 2009· Updated Jun 16, 2026
CVE-2009-1532
CVE-2009-1532
Description
Microsoft Internet Explorer 8 for Windows XP SP2 and SP3; 8 for Server 2003 SP2; 8 for Vista Gold, SP1, and SP2; and 8 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via "malformed row property references" that trigger an access of an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Objects Memory Corruption Vulnerability" or "HTML Object Memory Corruption Vulnerability."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
8- docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-019nvdPatchVendor Advisory
- www.securityfocus.com/archive/1/504208/100/0/threadednvdBroken LinkThird Party AdvisoryVDB Entry
- www.securitytracker.com/idnvdBroken LinkThird Party AdvisoryVDB Entry
- www.us-cert.gov/cas/techalerts/TA09-160A.htmlnvdBroken LinkThird Party AdvisoryUS Government Resource
- www.vupen.com/english/advisories/2009/1538nvdBroken LinkVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-09-041nvdBroken LinkThird Party AdvisoryVDB Entry
- osvdb.org/54951nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6244nvdBroken Link
News mentions
0No linked articles in our index yet.