SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#197852

Microsoft Internet Explorer fails to properly interpret HTML with certain layout combinations

Overview

A vulnerability in the way Microsoft Internet Explorer interprets malformed Web pages may lead to execution of arbitrary code.

I. Description

Microsoft Internet Explorer contatins a vulnerabilty that could be exploited when Internet Explorer attempts to interpret specially crafted Web pages. According to Microsoft Security Bulletin MS06-067:

    When Internet Explorer handles specially crafted HTML with certain HTML layout combinations it may corrupt system memory in such a way that an attacker could execute arbitrary code.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code with the privileges of the affected user or cause a denial-of-service condition.

III. Solution

Update

Microsoft has released an update to address this issue. See Microsoft Security Bulletin MS06-067 for more details.

Workarounds

Microsoft recommends the following workarounds to mitigate this vulnerability:

  • Read and send email in plain text format
  • Disable active scripting

Please see Microsoft Security Bulletin MS06-067 for details on these workarounds.

Systems Affected

VendorStatusDate Updated
Microsoft CorporationVulnerable14-Nov-2006

References


http://www.microsoft.com/technet/security/bulletin/ms06-067.mspx
http://www.zerodayinitiative.com/advisories/ZDI-06-041.html

Credit

This vulnerability was reported in Microsoft Security Bulletin MS06-067. Microsoft credits Sam Thomas, working with TippingPoint and the Zero Day Initiative for reporting this issue.

This document was written by Chris Taschner.

Other Information

Date Public11/14/2006
Date First Published11/15/2006 12:42:28 PM
Date Last Updated11/17/2006
CERT Advisory 
CVE NameCVE-2006-4687
US-CERT Technical Alerts 
Metric27.00
Document Revision14

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader