Internet Explorer Script Error Handling Memory Corruption Vulnerability

Posted on Tuesday, December 12, 2006 @ 23:52:47 CST in Security
by Raven

SECUNIA ADVISORY ID: SA20807

VERIFY ADVISORY: http://secunia.com/advisories/20807/

CRITICAL: Highly critical

IMPACT: System access

SOFTWARE: Microsoft Internet Explorer 6.x-http://secunia.com/product/11/

DESCRIPTION: Secunia Research has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an error within the exception handling of script errors. This can be exploited to corrupt memory via an HTML document containing specially crafted JavaScript that triggers certain errors simultaneously. Successful exploitation allows execution of arbitrary code.

SOLUTION: Apply patches.
Internet Explorer 6 SP1 installed on Windows 2000 SP4: http://www.microsoft.com/downloads/details.aspx?FamilyId=3CFC32FC-85CA-4EDA-890D-5E359F5F0019
Internet Explorer 6 for Windows XP SP2: http://www.microsoft.com/downloads/details.aspx?FamilyId=8B321744-B55E-4696-8B2C-B1D31672DA06
Internet Explorer 6 for Windows XP Professional x64 Edition: http://www.microsoft.com/downloads/details.aspx?FamilyId=8D841D1B-D0B1-46AF-87BD-7DAA8C31AF39
Internet Explorer 6 for Windows Server 2003 (optionally with SP1): http://www.microsoft.com/downloads/details.aspx?FamilyId=3E3A9693-D21B-4214-A16C-3FC22340E600
Internet Explorer 6 for Windows Server 2003 for Itanium-based systems (optionally with SP1): http://www.microsoft.com/downloads/details.aspx?FamilyId=9E3F7A2C-BFE1-48C5-8A8A-64A06BCDF219
Internet Explorer 6 for Windows Server 2003 x64 Edition: http://www.microsoft.com/downloads/details.aspx?FamilyId=F56065CE-6D28-479B-80A7-E04022454DE9

PROVIDED AND/OR DISCOVERED BY: Jakob Balle and Carsten Eiram, Secunia Research.

ORIGINAL ADVISORY:
Secunia Research: http://secunia.com/secunia_research/2006-58/
MS06-72 (KB925454): http://www.microsoft.com/technet/security/Bulletin/MS06-072.mspx
 
 
click Related        click Share
 
News ©

Site Info

Last SeenLast Seen
  • vashd1
  • neralex
Server TrafficServer Traffic
  • Total: 513,234,749
  • Today: 47,002
Server InfoServer Info
  • Apr 24, 2025
  • 04:47 am CDT