Microsoft Internet Explorer Visual Studio COM Object Instantiation Denial of Service Vulnerability
BID:19572
CVE-2006-4494 |Info
Microsoft Internet Explorer Visual Studio COM Object Instantiation Denial of Service Vulnerability
| Bugtraq ID: | 19572 |
| Class: | Design Error |
| CVE: |
CVE-2006-4494 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2006 12:00AM |
| Updated: | Jun 27 2007 03:28AM |
| Credit: | XSec is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Visual Studio 6.0 Microsoft Internet Explorer 6.0 SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Visual Studio COM Object Instantiation Denial of Service Vulnerability
Microsoft Internet Explorer is prone to a denial-of-service vulnerability that occurs when instantiating Visual Studio COM objects.
The vulnerability arises because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in denial-of-service conditions. Remote code execution may be possible, but this has not been confirmed.
This BID may be related to the issues described in BID 14511 (Microsoft Internet Explorer COM Object Instantiation Buffer Overflow Vulnerability) and BID 15061 Microsoft Internet Explorer COM Object Instantiation Variant Vulnerability). Note, however, that this issue affects a different set of COM objects that were not addressed in the previous BIDs.
Microsoft Internet Explorer is prone to a denial-of-service vulnerability that occurs when instantiating Visual Studio COM objects.
The vulnerability arises because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in denial-of-service conditions. Remote code execution may be possible, but this has not been confirmed.
This BID may be related to the issues described in BID 14511 (Microsoft Internet Explorer COM Object Instantiation Buffer Overflow Vulnerability) and BID 15061 Microsoft Internet Explorer COM Object Instantiation Variant Vulnerability). Note, however, that this issue affects a different set of COM objects that were not addressed in the previous BIDs.
Exploit / POC
Microsoft Internet Explorer Visual Studio COM Object Instantiation Denial of Service Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Microsoft Internet Explorer Visual Studio COM Object Instantiation Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Microsoft Internet Explorer Visual Studio COM Object Instantiation Denial of Service Vulnerability
References:
References:
- Internet Explorer Homepage (Microsoft)
- Visual Studio 6.0 Multiple COM Object Instantiation (XSec)