Zero Day Initiative Advisory 09-086 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required in that a user must visit a malicious web page. The specific flaw exists in the manipulation and parsing of certain HTML tags. The ordering of various objects in a malformed way results in memory corruption resulting in a call to a dangling pointer which can be further leveraged via a heap spray. Exploitation of this vulnerability will lead to remote system compromise under the credentials of the currently logged in user.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/83576/ZDI-09-086.txt
Source: https://packetstormsecurity.com/files/83576/Zero-Day-Initiative-Advisory-09-086.html

