Vulnerable Systems:
* Windows 2000/XP/2003 Internet Explorer 6.0 SP1
When Internet Explorer handles an DirectAnimation.PathControl COM object (daxctle.ocx) \ Spline method, Setting the first parameter to 0xffffffff will triggers an invalid memory \ write, That way, an attacker may DoS and possibly could execute arbitrary code.
Exploit:
<!--
// Internet Explorer (daxctle.ocx) Heap Overflow Vulnerability
// tested on Windows 2000 SP4/XP SP2/2003 SP1