A remote code execution vulnerability exists in Internet Explorer due to accesses to uninitialized memory in certain cases of DTML constructs. As a result, memory may be corrupted in such a way that an attacker could execute arbitrary code in the context of the logged-on user.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/71116/n.runs-SA-2008.008.txt
Source: https://packetstormsecurity.com/files/71116/n.runs-SA-2008.008.txt.html

