|
|
|
![]() |
Vulnerability Note VU#338828Microsoft Internet Explorer exception handling vulnerabilityOverviewMicrosoft Internet Explorer fails to properly handle exception conditions. This may allow a remote, unauthenticated attacker to execute arbitrary code.I. DescriptionInternet Explorer allows objects to register exception handlers. These handlers may not properly handle some conditions, which may cause memory corruption.II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system.III. SolutionApply an updateThis issue is addressed in Microsoft Security Bulletin MS06-021. This update removes exception handlers from Internet Explorer.
References
This vulnerability was reported by Secunia Research, who in turn credit Andreas Sandblad. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||