|
|
|
Vulnerability Note VU#820957Microsoft Internet Explorer 5.5 print template ActiveX control allows arbitrary command executionOverviewThe Internet Explorer 5.5 Print Template feature contains a vulnerability that allows a web page author to execute arbitrary code as the user viewing the web page.I. DescriptionInternet Explorer version 5.5 supports a feature called "print templates" which allows a web page author to specify a custom print format for the web page. Because the print templates are allowed to execute ActiveX controls, including those that are not marked "safe for scripting", a web page author can use a custom print template to execute arbitrary code as the user printing the web page.II. ImpactA user printing a malicious web page may allow a remote attacker to execute arbitrary code.III. SolutionApply a PatchMicrosoft has published patches correcting this vulnerability. The patches are listed in their advisory at: Systems Affected
References
Thanks to Warren R. Greer for discovering this vulnerability. This document was written by Cory F. Cohen.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||