Internet Explorer 6 ComponentFromPoint() Memory Disclosure and Code Execution
17 Oct. 2008
Summary
There is a bug in Internet Explorer 6 JavaScript implementation enabling remote memory disclosure and remote code execution. The vulnerability is caused by improper implementation of componentFromPoint() method of XML object.
The vulnerability is triggered by errornous behavior of componentFromPoint() method when invoked on a newly created xml
object.
Impact:
This vulnerability can be used (trivially) to remotely disclose Internet Explorer's memory when a victim visits a specially crafted web page or (less trivially) to achieve remote code execution when a victim visits a specially crafted web page.