|
|
|
|
| |
Credit:
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-10-034
|
| |
Vulnerable Systems:
Microsoft Internet Explorer 6
User interaction is required to exploit this vulnerability in that the target must visit a malicious page.
The specific flaw exists within the Tabular Data Control ActiveX module. Specifically, if provided a malicious DataURL parameter a stack corruption may occur in the function CTDCCtl::SecurityCHeckDataURL. This can be leveraged to execute arbitrary code under the context of the current user.
Patch Availability:
Microsoft has issued an update to correct this vulnerability. More details can be found at:
http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx
CVE Information:
CVE-2010-0805
Disclosure Timeline:
2009-10-20 - Vulnerability reported to vendor
2010-04-02 - Coordinated public release of advisory
|
|
|
|
|