Microsoft Internet Explorer TSUserEX.DLL ActiveX Control Memory Corruption Vulnerability
BID:19570
CVE-2006-4219 |Info
Microsoft Internet Explorer TSUserEX.DLL ActiveX Control Memory Corruption Vulnerability
| Bugtraq ID: | 19570 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2006 12:00AM |
| Updated: | Aug 29 2006 05:14PM |
| Credit: | nop is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer TSUserEX.DLL ActiveX Control Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a memory-corruption vulnerability. This is related to the handling of the 'tsuserex.dll' COM object ActiveX control.
Attackers may exploit this issue via a malicious web page to execute arbitrary code in the context of the currently logged-in user. Exploitation attempts may lead to a denial-of-service condition as well. Attackers may also employ HTML email to carry out an attack.
Microsoft Internet Explorer is prone to a memory-corruption vulnerability. This is related to the handling of the 'tsuserex.dll' COM object ActiveX control.
Attackers may exploit this issue via a malicious web page to execute arbitrary code in the context of the currently logged-in user. Exploitation attempts may lead to a denial-of-service condition as well. Attackers may also employ HTML email to carry out an attack.
Exploit / POC
Microsoft Internet Explorer TSUserEX.DLL ActiveX Control Memory Corruption Vulnerability
Attackers can exploit this issue via a web client.
A proof of concept is available to crash Internet Explorer.
Attackers can exploit this issue via a web client.
A proof of concept is available to crash Internet Explorer.
Solution / Fix
Microsoft Internet Explorer TSUserEX.DLL ActiveX Control Memory Corruption Vulnerability
Solution:
Currently we are not aware of any solutions for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any solutions for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Microsoft Internet Explorer TSUserEX.DLL ActiveX Control Memory Corruption Vulnerability
References:
References: