Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2007-12-11.1

iDefense Security Advisory 12.11.07 – Remote exploitation of a heap corruption vulnerability in Microsoft Corp.’s Internet Explorer web browser allows attackers to execute arbitrary code in the context of the current user. The vulnerability lies in the JavaScript setExpression method, which is implemented in mshtml.dll. When malformed parameters are supplied, memory can be corrupted in a way that results in Internet Explorer accessing a previously deleted object. By creating a specially crafted web page, it is possible for an attacker to control the contents of the memory pointed to by the released object. This allows an attacker to execute arbitrary code. As of April 5th, 2007, iDefense testing shows that Internet Explorer 6.0 and Internet Explorer 7.0 with all available security patches are vulnerable. Older versions of Internet Explorer may also be vulnerable.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/61764/12.11.07-1.txt

Source: https://packetstormsecurity.com/files/61764/iDEFENSE-Security-Advisory-2007-12-11.1.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534