Microsoft Internet Explorer DHTML Handling Memory Corruption Vulnerability (MS09-019)
14 Jun. 2009
Summary
A memory corruption vulnerability exists in the DHTML handling of Microsoft's Internet Explorer which allows a remote attacker to compromise a system through a malicious site.
Vulnerable Systems:
* Microsoft Internet Explorer version 8 and earlier
The vulnerability occurs when Internet Explorer processes special DHTML functions. A crash may happen when destroying a window after making a sequence of calls on the "tr" element. These calls are linked to the insertion, deletion and attributes of a table cell. The crash may then allow the arbitrary execution of code on the browsers machine.