Details

Id:               0F5F AVR:OOB iexplore.exe!MSHTML.dll!`CBackgroundInfo::Property<...>'::`7'::`dynamic atexit destructor for 'fieldDefaultValue''
Description:      Access violation while reading memory at 0x625960D000; 0/0x0 bytes beyond a 16/0x10 byte memory block at 0x625960CFF0
Process binary:   iexplore.exe
Code:             MSHTML.dll!`CBackgroundInfo::Property<CBackgroundImage>'::`7'::`dynamic atexit destructor for 'fieldDefaultValue'' + 0xA9CFA (this may not be correct)
Security impact:  Potentially exploitable security issue

Stack

MSHTML.dll!`CBackgroundInfo::Property<CBackgroundImage>'::`7'::`dynamic atexit destructor for 'fieldDefaultValue'' + 0xA9CFA (this may not be correct) (0F in id)
MSHTML.dll!CCSSStyleDeclaration::setPropertyInternal + 0x130 (5F in id)
MSHTML.dll!CWritableCSSStyleDeclaration::setPropertyInternal + 0x21
MSHTML.dll!CCSSStyleDeclaration::Var_setProperty + 0x154
MSHTML.dll!CFastDOM::CCSSStyleDeclaration::Trampoline_setProperty + 0x77
jscript9.dll!amd64_CallFunction + 0x93
jscript9.dll!Js::JavascriptExternalFunction::ExternalFunctionThunk + 0x178
jscript9.dll!amd64_CallFunction + 0x93
jscript9.dll!Js::InterpreterStackFrame::Process + 0x21B3 (this may not be correct)
jscript9.dll!Js::InterpreterStackFrame::InterpreterThunk<1> + 0x386
0x625A6C0FC3
jscript9.dll!amd64_CallFunction + 0x93
jscript9.dll!Js::JavascriptFunction::CallFunction<1> + 0x6D
jscript9.dll!Js::JavascriptFunction::CallRootFunction + 0x110
jscript9.dll!ScriptSite::CallRootFunction + 0x63
jscript9.dll!ScriptSite::Execute + 0x122
jscript9.dll!ScriptEngine::ExecutePendingScripts + 0x208
jscript9.dll!ScriptEngine::ParseScriptTextCore + 0x4A5
jscript9.dll!ScriptEngine::ParseScriptText + 0xC4
MSHTML.dll!CActiveScriptHolder::ParseScriptText + 0xC1
MSHTML.dll!CJScript9Holder::ParseScriptText + 0xF7
MSHTML.dll!CScriptCollection::ParseScriptText + 0x28C
MSHTML.dll!CScriptData::CommitCode + 0x3D9
MSHTML.dll!CScriptData::Execute + 0x283
MSHTML.dll!CHtmScriptParseCtx::Execute + 0x101
MSHTML.dll!CHtmParseBase::Execute + 0x235
MSHTML.dll!CHtmPost::Broadcast + 0x80
MSHTML.dll!CHtmPost::Exec + 0x51A
MSHTML.dll!CHtmPost::Run + 0x3F
MSHTML.dll!PostManExecute + 0x70
MSHTML.dll!PostManResume + 0xA1
MSHTML.dll!CHtmPost::OnDwnChanCallback + 0x43
MSHTML.dll!CDwnChan::OnMethodCall + 0x41
MSHTML.dll!GlobalWndOnMethodCall + 0x236
MSHTML.dll!GlobalWndProc + 0x174
USER32.dll!UserCallWinProcCheckWow + 0x149
USER32.dll!DispatchMessageWorker + 0x396
IEFRAME.dll!CTabWindow::_TabWindowThreadProc + 0x555
IEFRAME.dll!LCIETab_ThreadProc + 0x3A3
iertutil.dll!IsoCreateComponentByCreDat + 0xCF
IEShims.dll!NS_CreateThread::DesktopIE_ThreadProc + 0x9F
KERNEL32.DLL!BaseThreadInitThunk + 0x22
ntdll.dll!RtlUserThreadStart + 0x34

Binary information

MSHTML.dll

    Loaded symbol image file: C:\Windows\SYSTEM32\MSHTML.dll
    Image path: C:\Windows\SYSTEM32\MSHTML.dll
    Image name: MSHTML.dll
    Timestamp:        Sat Feb 06 11:42:14 2016 (56B5CE06)
    CheckSum:         018A91F9
    ImageSize:        018AE000
    File version:     11.0.9600.18212
    Product version:  11.0.9600.18212
    File flags:       0 (Mask 3F)
    File OS:          40004 NT Win32
    File type:        2.0 Dll
    File date:        00000000.00000000
    Translations:     0409.04b0
    CompanyName:      Microsoft Corporation
    ProductName:      Internet Explorer
    InternalName:     MSHTML
    OriginalFilename: MSHTML.DLL
    ProductVersion:   11.00.9600.18212
    FileVersion:      11.00.9600.18212 (winblue_ltsb_escrow.160205-2245)
    FileDescription:  Microsoft (R) HTML Viewer
    LegalCopyright:   � Microsoft Corporation. All rights reserved.

iexplore.exe

    Image path: iexplore.exe
    Image name: iexplore.exe
    Timestamp:        Sun Nov 08 21:24:32 2015 (563FAF80)
    CheckSum:         000D388A
    ImageSize:        000C8000
    File version:     11.0.9600.18123
    Product version:  11.0.9600.18123
    File flags:       0 (Mask 3F)
    File OS:          40004 NT Win32
    File type:        1.0 App
    File date:        00000000.00000000
    Translations:     0409.04b0
    CompanyName:      Microsoft Corporation
    ProductName:      Internet Explorer
    InternalName:     iexplore
    OriginalFilename: IEXPLORE.EXE
    ProductVersion:   11.00.9600.18123
    FileVersion:      11.00.9600.18123 (winblue_ltsb.151108-1002)
    FileDescription:  Internet Explorer
    LegalCopyright:   � Microsoft Corporation. All rights reserved.

Debugger IO


Microsoft (R) Windows Debugger Version 6.3.9600.16384 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

CommandLine: "C:\Program Files\Internet Explorer\iexplore.exe" http://J3:28876/

************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*http://msdl.microsoft.com/download/symbols
Deferred                                       cache*C:\Symbols
Deferred                                       cache*\\server\Symbols
Deferred                                       srv*http://symbols.mozilla.org/firefox
Deferred                                       srv*http://chromium-browser-symsrv.commondatastorage.googleapis.com
Symbol search path is: srv*http://msdl.microsoft.com/download/symbols;cache*C:\Symbols;cache*\\server\Symbols;srv*http://symbols.mozilla.org/firefox;srv*http://chromium-browser-symsrv.commondatastorage.googleapis.com
Executable search path is: 
ModLoad: 00007ff6`e3420000 00007ff6`e34e8000   iexplore.exe
ModLoad: 00007ffd`dd320000 00007ffd`dd4cd000   ntdll.dll
ModLoad: 00007ffd`d1c70000 00007ffd`d1cdc000   C:\Windows\system32\verifier.dll
Page heap: pid 0xA3584: page heap enabled with flags 0x3.
ModLoad: 00007ffd`db8c0000 00007ffd`db9fe000   C:\Windows\system32\KERNEL32.DLL
ModLoad: 00007ffd`da820000 00007ffd`da935000   C:\Windows\system32\KERNELBASE.dll
ModLoad: 00007ffd`d9010000 00007ffd`d909e000   C:\Windows\system32\apphelp.dll
SHIMVIEW: ShimInfo(Complete)
ModLoad: 00007ffd`dbc60000 00007ffd`dbdd7000   C:\Windows\system32\USER32.dll
ModLoad: 00007ffd`db740000 00007ffd`db7ea000   C:\Windows\system32\msvcrt.dll
ModLoad: 00007ffd`d89c0000 00007ffd`d8a72000   C:\Windows\SYSTEM32\shcore.dll
ModLoad: 00007ffd`d4200000 00007ffd`d44c8000   C:\Windows\SYSTEM32\iertutil.dll
ModLoad: 00007ffd`dae50000 00007ffd`dafa0000   C:\Windows\system32\GDI32.dll
ModLoad: 00007ffd`dba00000 00007ffd`dbc11000   C:\Windows\SYSTEM32\combase.dll
ModLoad: 00007ffd`dab50000 00007ffd`dac91000   C:\Windows\system32\RPCRT4.dll
(a3584.a2fc4): Break instruction exception - code 80000003 (first chance)
ntdll!LdrpDoDebuggerBreak+0x30:
00007ffd`dd3e1b90 cc              int     3

Create process 669060 exception.
0:000> g
(a3584.a3b48): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
00007ffd`bdb8419e 66394f08        cmp     word ptr [rdi+8],cx ds:00000062`5960d000=????

0:011> .lastevent
Last event: a3584.a3b48: Access violation - code c0000005 (first chance)
  debugger time: Fri Feb 26 21:58:45.538 2016 (UTC + 1:00)

0:011> |.
.  0 id: a3584 create name: iexplore.exe

0:011> .exr -1
ExceptionAddress: 00007ffdbdb8419e (MSHTML!`CBackgroundInfo::Property<CBackgroundImage>'::`7'::`dynamic atexit destructor for 'fieldDefaultValue''+0x00000000000a9cfa)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: 000000625960d000
Attempt to read from address 000000625960d000

0:011> lm on
start             end                 module name
00007ff6`e3420000 00007ff6`e34e8000   iexplore iexplore.exe
00007ffd`bd210000 00007ffd`beabe000   MSHTML   MSHTML.dll  
00007ffd`c03c0000 00007ffd`c098f000   jscript9 jscript9.dll
00007ffd`c7970000 00007ffd`c7995000   mssprxy  mssprxy.dll 
00007ffd`c79b0000 00007ffd`c8780000   IEFRAME  IEFRAME.dll 
00007ffd`cae20000 00007ffd`cb11b000   explorerframe explorerframe.dll
00007ffd`cd740000 00007ffd`cd74c000   settingsyncpolicy settingsyncpolicy.dll
00007ffd`cda60000 00007ffd`cdb2a000   ieapfltr ieapfltr.dll
00007ffd`ce870000 00007ffd`ce943000   SettingSyncCore SettingSyncCore.dll
00007ffd`ce950000 00007ffd`ce9e9000   IEUI     IEUI.dll    
00007ffd`cee70000 00007ffd`cef2a000   ieproxy  ieproxy.dll 
00007ffd`d0440000 00007ffd`d048d000   Windows_Graphics Windows.Graphics.dll
00007ffd`d1010000 00007ffd`d12d3000   actxprxy actxprxy.dll
00007ffd`d1bd0000 00007ffd`d1c32000   IEShims  IEShims.dll 
00007ffd`d1c70000 00007ffd`d1cdc000   verifier verifier.dll
00007ffd`d24e0000 00007ffd`d24ec000   Secur32  Secur32.dll 
00007ffd`d3030000 00007ffd`d3094000   ninput   ninput.dll  
00007ffd`d3110000 00007ffd`d312f000   vaultcli vaultcli.dll
00007ffd`d3880000 00007ffd`d388a000   rasadhlp rasadhlp.dll
00007ffd`d3b60000 00007ffd`d3b9e000   MLANG    MLANG.dll   
00007ffd`d3cf0000 00007ffd`d3db9000   winhttp  winhttp.dll 
00007ffd`d3f70000 00007ffd`d41f3000   WININET  WININET.dll 
00007ffd`d4200000 00007ffd`d44c8000   iertutil iertutil.dll
00007ffd`d44d0000 00007ffd`d44d7000   MSIMG32  MSIMG32.dll 
00007ffd`d44e0000 00007ffd`d4665000   urlmon   urlmon.dll  
00007ffd`d4e30000 00007ffd`d52b1000   d2d1     d2d1.dll    
00007ffd`d56f0000 00007ffd`d5718000   IDStore  IDStore.dll 
00007ffd`d5910000 00007ffd`d592f000   SAMLIB   SAMLIB.dll  
00007ffd`d5d50000 00007ffd`d5dbb000   fwpuclnt fwpuclnt.dll
00007ffd`d5f70000 00007ffd`d5f7a000   WINNSI   WINNSI.DLL  
00007ffd`d5f90000 00007ffd`d5fba000   IPHLPAPI IPHLPAPI.DLL
00007ffd`d6120000 00007ffd`d6130000   msimtf   msimtf.dll  
00007ffd`d6130000 00007ffd`d613c000   ondemandconnroutehelper ondemandconnroutehelper.dll
00007ffd`d64c0000 00007ffd`d663f000   PROPSYS  PROPSYS.dll 
00007ffd`d6800000 00007ffd`d69ec000   DWrite   DWrite.dll  
00007ffd`d6bc0000 00007ffd`d6c2a000   oleacc   oleacc.dll  
00007ffd`d6dc0000 00007ffd`d6de2000   sppc     sppc.dll    
00007ffd`d6df0000 00007ffd`d6e1b000   SLC      SLC.dll     
00007ffd`d6ec0000 00007ffd`d7945000   atidxx64 atidxx64.dll
00007ffd`d7a90000 00007ffd`d7ab6000   atiuxp64 atiuxp64.dll
00007ffd`d7c80000 00007ffd`d7d24000   DUser    DUser.dll   
00007ffd`d7d30000 00007ffd`d7d3a000   VERSION  VERSION.dll 
00007ffd`d7d40000 00007ffd`d7e8c000   aticfx64 aticfx64.dll
00007ffd`d7f00000 00007ffd`d817b000   comctl32 comctl32.dll
00007ffd`d8180000 00007ffd`d8207000   dxgi     dxgi.dll    
00007ffd`d8210000 00007ffd`d8443000   d3d11    d3d11.dll   
00007ffd`d8610000 00007ffd`d87be000   windowscodecs windowscodecs.dll
00007ffd`d87c0000 00007ffd`d87e1000   dwmapi   dwmapi.dll  
00007ffd`d87f0000 00007ffd`d89b1000   DUI70    DUI70.dll   
00007ffd`d89c0000 00007ffd`d8a72000   shcore   shcore.dll  
00007ffd`d8a80000 00007ffd`d8ae0000   dcomp    dcomp.dll   
00007ffd`d9010000 00007ffd`d909e000   apphelp  apphelp.dll 
00007ffd`d90a0000 00007ffd`d90aa000   DPAPI    DPAPI.dll   
00007ffd`d90b0000 00007ffd`d90bb000   kernel_appcore kernel.appcore.dll
00007ffd`d90f0000 00007ffd`d9219000   uxtheme  uxtheme.dll 
00007ffd`d9980000 00007ffd`d99b6000   rsaenh   rsaenh.dll  
00007ffd`d9a90000 00007ffd`d9ab1000   USERENV  USERENV.dll 
00007ffd`d9ac0000 00007ffd`d9b06000   powrprof powrprof.dll
00007ffd`d9b50000 00007ffd`d9bf4000   DNSAPI   DNSAPI.dll  
00007ffd`d9d50000 00007ffd`d9da9000   mswsock  mswsock.dll 
00007ffd`d9db0000 00007ffd`d9dd0000   CRYPTSP  CRYPTSP.dll 
00007ffd`da000000 00007ffd`da026000   bcrypt   bcrypt.dll  
00007ffd`da310000 00007ffd`da33e000   SSPICLI  SSPICLI.DLL 
00007ffd`da340000 00007ffd`da3a3000   bcryptPrimitives bcryptPrimitives.dll
00007ffd`da3b0000 00007ffd`da3bb000   CRYPTBASE CRYPTBASE.dll
00007ffd`da3c0000 00007ffd`da459000   sxs      sxs.dll     
00007ffd`da470000 00007ffd`da485000   profapi  profapi.dll 
00007ffd`da520000 00007ffd`da531000   MSASN1   MSASN1.dll  
00007ffd`da540000 00007ffd`da71f000   CRYPT32  CRYPT32.dll 
00007ffd`da7d0000 00007ffd`da81f000   CFGMGR32 CFGMGR32.dll
00007ffd`da820000 00007ffd`da935000   KERNELBASE KERNELBASE.dll
00007ffd`daa20000 00007ffd`daad6000   comdlg32 comdlg32.dll
00007ffd`dab50000 00007ffd`dac91000   RPCRT4   RPCRT4.dll  
00007ffd`dacb0000 00007ffd`dae44000   ole32    ole32.dll   
00007ffd`dae50000 00007ffd`dafa0000   GDI32    GDI32.dll   
00007ffd`dafa0000 00007ffd`db04a000   ADVAPI32 ADVAPI32.dll
00007ffd`db050000 00007ffd`db0a9000   sechost  sechost.dll 
00007ffd`db0b0000 00007ffd`db0b9000   NSI      NSI.dll     
00007ffd`db0c0000 00007ffd`db29a000   SETUPAPI SETUPAPI.dll
00007ffd`db2a0000 00007ffd`db3f2000   MSCTF    MSCTF.dll   
00007ffd`db400000 00007ffd`db454000   SHLWAPI  SHLWAPI.dll 
00007ffd`db610000 00007ffd`db66a000   WS2_32   WS2_32.dll  
00007ffd`db670000 00007ffd`db726000   clbcatq  clbcatq.dll 
00007ffd`db740000 00007ffd`db7ea000   msvcrt   msvcrt.dll  
00007ffd`db7f0000 00007ffd`db8b1000   OLEAUT32 OLEAUT32.dll
00007ffd`db8c0000 00007ffd`db9fe000   KERNEL32 KERNEL32.DLL
00007ffd`dba00000 00007ffd`dbc11000   combase  combase.dll 
00007ffd`dbc20000 00007ffd`dbc56000   IMM32    IMM32.DLL   
00007ffd`dbc60000 00007ffd`dbdd7000   USER32   USER32.dll  
00007ffd`dbdf0000 00007ffd`dd31a000   SHELL32  SHELL32.dll 
00007ffd`dd320000 00007ffd`dd4cd000   ntdll    ntdll.dll   

0:011> kn 0x64
 # Child-SP          RetAddr           Call Site
00 00000062`5e83a870 00007ffd`be0de7f0 MSHTML!`CBackgroundInfo::Property<CBackgroundImage>'::`7'::`dynamic atexit destructor for 'fieldDefaultValue''+0xa9cfa
01 00000062`5e83ab30 00007ffd`be0de881 MSHTML!CCSSStyleDeclaration::setPropertyInternal+0x130
02 00000062`5e83abc0 00007ffd`be0dc210 MSHTML!CWritableCSSStyleDeclaration::setPropertyInternal+0x21
03 00000062`5e83ac00 00007ffd`be1dd417 MSHTML!CCSSStyleDeclaration::Var_setProperty+0x154
04 00000062`5e83ac90 00007ffd`c03d1e93 MSHTML!CFastDOM::CCSSStyleDeclaration::Trampoline_setProperty+0x77
05 00000062`5e83ad10 00007ffd`c03d77d8 jscript9!amd64_CallFunction+0x93
06 00000062`5e83ad70 00007ffd`c03d1e93 jscript9!Js::JavascriptExternalFunction::ExternalFunctionThunk+0x178
07 00000062`5e83ae10 00007ffd`c06129f5 jscript9!amd64_CallFunction+0x93
08 00000062`5e83ae70 00007ffd`c03d6220 jscript9!Js::InterpreterStackFrame::Process+0x21b3
09 00000062`5e83b1f0 00000062`5a6c0fc3 jscript9!Js::InterpreterStackFrame::InterpreterThunk<1>+0x386
0a 00000062`5e83b4a0 00007ffd`c03d1e93 0x00000062`5a6c0fc3
0b 00000062`5e83b4d0 00007ffd`c03d1961 jscript9!amd64_CallFunction+0x93
0c 00000062`5e83b520 00007ffd`c03d1b6e jscript9!Js::JavascriptFunction::CallFunction<1>+0x6d
0d 00000062`5e83b560 00007ffd`c03d1c6f jscript9!Js::JavascriptFunction::CallRootFunction+0x110
0e 00000062`5e83b640 00007ffd`c03d1bc8 jscript9!ScriptSite::CallRootFunction+0x63
0f 00000062`5e83b6a0 00007ffd`c041f072 jscript9!ScriptSite::Execute+0x122
10 00000062`5e83b730 00007ffd`c041e7d9 jscript9!ScriptEngine::ExecutePendingScripts+0x208
11 00000062`5e83b820 00007ffd`c0420bc4 jscript9!ScriptEngine::ParseScriptTextCore+0x4a5
12 00000062`5e83b980 00007ffd`bd60cda1 jscript9!ScriptEngine::ParseScriptText+0xc4
13 00000062`5e83ba30 00007ffd`bd60cc0b MSHTML!CActiveScriptHolder::ParseScriptText+0xc1
14 00000062`5e83bab0 00007ffd`bd60c895 MSHTML!CJScript9Holder::ParseScriptText+0xf7
15 00000062`5e83bb60 00007ffd`bd60dc6b MSHTML!CScriptCollection::ParseScriptText+0x28c
16 00000062`5e83bc40 00007ffd`bd60d7f5 MSHTML!CScriptData::CommitCode+0x3d9
17 00000062`5e83be10 00007ffd`bd60d581 MSHTML!CScriptData::Execute+0x283
18 00000062`5e83bed0 00007ffd`bdaaea02 MSHTML!CHtmScriptParseCtx::Execute+0x101
19 00000062`5e83bf10 00007ffd`bdae5015 MSHTML!CHtmParseBase::Execute+0x235
1a 00000062`5e83bfb0 00007ffd`bd29d7b8 MSHTML!CHtmPost::Broadcast+0x80
1b 00000062`5e83bff0 00007ffd`bd5c7ddf MSHTML!CHtmPost::Exec+0x51a
1c 00000062`5e83c200 00007ffd`bd5c7d30 MSHTML!CHtmPost::Run+0x3f
1d 00000062`5e83c230 00007ffd`bd5c8dee MSHTML!PostManExecute+0x70
1e 00000062`5e83c2b0 00007ffd`bd5cd253 MSHTML!PostManResume+0xa1
1f 00000062`5e83c2f0 00007ffd`bd3dc05c MSHTML!CHtmPost::OnDwnChanCallback+0x43
20 00000062`5e83c340 00007ffd`bda9c988 MSHTML!CDwnChan::OnMethodCall+0x41
21 00000062`5e83c370 00007ffd`bd219c99 MSHTML!GlobalWndOnMethodCall+0x236
22 00000062`5e83c410 00007ffd`dbc623fd MSHTML!GlobalWndProc+0x174
23 00000062`5e83c490 00007ffd`dbc6249d USER32!UserCallWinProcCheckWow+0x149
24 00000062`5e83c560 00007ffd`c79b4563 USER32!DispatchMessageWorker+0x396
25 00000062`5e83c5e0 00007ffd`c7a4c2cb IEFRAME!CTabWindow::_TabWindowThreadProc+0x555
26 00000062`5e83f860 00007ffd`d422fbbf IEFRAME!LCIETab_ThreadProc+0x3a3
27 00000062`5e83f990 00007ffd`d1be925f iertutil!IsoCreateComponentByCreDat+0xcf
28 00000062`5e83f9c0 00007ffd`db8c13d2 IEShims!NS_CreateThread::DesktopIE_ThreadProc+0x9f
29 00000062`5e83fa10 00007ffd`dd3354e4 KERNEL32!BaseThreadInitThunk+0x22
2a 00000062`5e83fa40 00000000`00000000 ntdll!RtlUserThreadStart+0x34

0:011> ~s
00007ffd`bdb8419e 66394f08        cmp     word ptr [rdi+8],cx ds:00000062`5960d000=????

0:011> !heap -p -a 0x625960D000
    address 000000625960d000 found in
    _DPH_HEAP_ROOT @ 624ffc1000
    in busy allocation (  DPH_HEAP_BLOCK:         UserAddr         UserSize -         VirtAddr         VirtSize)
                              6258e37af8:       625960cff0               10 -       625960c000             2000
    00007ffddd411d82 ntdll!RtlDebugAllocateHeap+0x000000000000004e
    00007ffddd3c9b60 ntdll!RtlpAllocateHeap+0x0000000000077de0
    00007ffddd350dad ntdll!RtlAllocateHeap+0x000000000000017d
    00007ffddb7f16cb OLEAUT32!SysAllocString+0x0000000000000073
    00007ffdbd2151c5 MSHTML!FormsAllocStringW+0x0000000000000025
    00007ffdbd54552b MSHTML!CAttrArray::Set+0x000000000000063b
    00007ffdbdab137a MSHTML!CBase::InvokeAA+0x000000000000016a
    00007ffdbd439e4b MSHTML!CElement::ie9_setAttributeNSInternal+0x0000000000000289
    00007ffdbd43a124 MSHTML!CElement::Var_setAttribute+0x00000000000001d7
    00007ffdbd439f2d MSHTML!CFastDOM::CElement::Trampoline_setAttribute+0x000000000000006d
    00007ffdc03d1e93 jscript9!amd64_CallFunction+0x0000000000000093
    00007ffdc03d77d8 jscript9!Js::JavascriptExternalFunction::ExternalFunctionThunk+0x0000000000000178
    00007ffdc03d1e93 jscript9!amd64_CallFunction+0x0000000000000093
    00007ffdc06129f5 jscript9!Js::InterpreterStackFrame::Process+0x00000000000021b3
    00007ffdc03d6220 jscript9!Js::InterpreterStackFrame::InterpreterThunk<1>+0x0000000000000386
    000000625a6c0fc3 +0x000000625a6c0fc3

 

0:011> lm M *iexplore.exe
start             end                 module name
00007ff6`e3420000 00007ff6`e34e8000   iexplore   (deferred)             

0:011> lmv m *MSHTML
start             end                 module name
00007ffd`bd210000 00007ffd`beabe000   MSHTML     (pdb symbols)          c:\symbols\mshtml.pdb\D1C8BD717D01437AA418976CBD377EDC2\mshtml.pdb
    Loaded symbol image file: C:\Windows\SYSTEM32\MSHTML.dll
    Image path: C:\Windows\SYSTEM32\MSHTML.dll
    Image name: MSHTML.dll
    Timestamp:        Sat Feb 06 11:42:14 2016 (56B5CE06)
    CheckSum:         018A91F9
    ImageSize:        018AE000
    File version:     11.0.9600.18212
    Product version:  11.0.9600.18212
    File flags:       0 (Mask 3F)
    File OS:          40004 NT Win32
    File type:        2.0 Dll
    File date:        00000000.00000000
    Translations:     0409.04b0
    CompanyName:      Microsoft Corporation
    ProductName:      Internet Explorer
    InternalName:     MSHTML
    OriginalFilename: MSHTML.DLL
    ProductVersion:   11.00.9600.18212
    FileVersion:      11.00.9600.18212 (winblue_ltsb_escrow.160205-2245)
    FileDescription:  Microsoft (R) HTML Viewer
    LegalCopyright:   � Microsoft Corporation. All rights reserved.

0:011> lmv m *iexplore
start             end                 module name
00007ff6`e3420000 00007ff6`e34e8000   iexplore   (deferred)             
    Image path: iexplore.exe
    Image name: iexplore.exe
    Timestamp:        Sun Nov 08 21:24:32 2015 (563FAF80)
    CheckSum:         000D388A
    ImageSize:        000C8000
    File version:     11.0.9600.18123
    Product version:  11.0.9600.18123
    File flags:       0 (Mask 3F)
    File OS:          40004 NT Win32
    File type:        1.0 App
    File date:        00000000.00000000
    Translations:     0409.04b0
    CompanyName:      Microsoft Corporation
    ProductName:      Internet Explorer
    InternalName:     iexplore
    OriginalFilename: IEXPLORE.EXE
    ProductVersion:   11.00.9600.18123
    FileVersion:      11.00.9600.18123 (winblue_ltsb.151108-1002)
    FileDescription:  Internet Explorer
    LegalCopyright:   � Microsoft Corporation. All rights reserved.

0:011> q
quit: