Arbitrary Code Execution in Microsoft Internet Explorer - 18 Dec 2004
A vulnerability exists in Microsoft Internet Explorer (IE) that could result in the execution of arbitrary code on the vulnerable system.
December 17, 2004
Reported December 1, 2004, byMicrosoft
VERSIONS AFFECTED
DESCRIPTION
A vulnerability exists in Microsoft Internet Explorer (IE) that could result inthe execution of arbitrary code on the vulnerable system. Heap-based bufferoverflow in IE 6.0 allows remote attackers to execute arbitrary code via longSRC or NAME attributes in IFRAME, FRAME, and EMBED elements.
VENDOR RESPONSE
Microsoft has released SecurityBulletin MS04-040, "Cumulative Security Update for InternetExplorer (889293)," to address this vulnerability and recommends thataffected users immediately apply the appropriate patch listed in the bulletin.
CREDIT
Discovered by Microsoft.
About the Author
You May Also Like