Home » News » Critical Vulnerability in Inte ...

News by JavaScriptSearch


Critical Vulnerability in Internet Explorer Discovered

 

JavaScriptSearch
Thursday, March 23, 2006; 08:48 AM

Secunia Research has discovered a vulnerability in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an error in the processing of the "createTextRange()" method call applied on a radio button control. This can be exploited by e.g. a malicious web site to corrupt memory in a way, which allows the program flow to be redirected to the heap.

Successful exploitation allows execution of arbitrary code.

The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2. The vulnerability has also been confirmed in Internet Explorer 7 Beta 2 Preview (January edition). Other versions may also be affected.

A solution to the problem is disabling Active Scripting support. Microsoft plans to release a pre-patch advisory with workarounds for the "highly critical" vulnerability.


Advertisement

Partners

Related Resources

Other Resources

arrow