|
|
|
Vulnerability Note VU#390044Microsoft JScript memory corruption vulnerabilityOverviewMicrosoft JScript contains a memory corruption vulnerability. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.I. DescriptionMicrosoft JScriptAccording to Microsoft Security Bulletin MS06-023:
Microsoft JScript fails to properly release objects allowing in a memory corruption vulnerability to occur. When a specially crafted JScript file, or specially crafted web page containing JScript is accessed, system memory can be corrupted in a way that could allow a remote attacker to execute arbitrary code. Considerations For more information refer to Microsoft Security Bulletin MS06-023 II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code. If the attacked user is running with administrative privileges, the attacker could take complete control of an affected system.III. SolutionApply a patch from MicrosoftMicrosoft addresses this vulnerability with the updates listed in Microsoft Security Bulletin MS06-023.
References
This vulnerability was reported in Microsoft Security Bulletin MS06-023. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||