|
|
|
![]() |
Vulnerability Note VU#959649Microsoft Internet Explorer fails to properly handle embedded objectsOverviewMicrosoft Internet Explorer (IE) does not properly handle embedded dynamic objects. This vulnerability may allow a remote attacker to execute arbitrary code.I. DescriptionIOleClientSite interfaceAccording to Microsoft Security Bulletin MS06-013,
The Problem IE fails to properly handle embedded dynamic objects allowing a remote attacker to gain access to IOleClientSite information. An attacker may be able to leverage that information in a way that could allow them to bypass IE security settings. Considerations More information is available in Microsoft Security Bulletin MS06-013. II. ImpactBy convincing a user to open a specially crafted web page, a remote unauthenticated attacker can execute arbitrary code on a vulnerable.III. SolutionApply an UpdateThis issue is addressed in Microsoft Security Bulletin MS06-013.
References
This vulnerability was reported in Microsoft Security Bulletin MS06-013. Microsoft credits Heiko Schultze of SAP with providing information regarding this vulnerability. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||