Retired: Microsoft Internet Explorer Unspecified Code Execution Vulnerability
BID:20797
Info
Retired: Microsoft Internet Explorer Unspecified Code Execution Vulnerability
| Bugtraq ID: | 20797 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2006 12:00AM |
| Updated: | Nov 02 2006 06:22PM |
| Credit: | Michal Bucko <[email protected]> reported this issue. The original discoverer of this issue is currently unknown. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Retired: Microsoft Internet Explorer Unspecified Code Execution Vulnerability
Microsoft Internet Explorer is prone to an unspecified vulnerability that results in arbitrary code execution.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the vulnerable application. This facilitates the remote compromise of affected computers.
Internet Explorer 6 is vulnerable to this issue; other versions may also be affected.
An exploit for this issue is reportedly in the wild.
Further investigation reveals this issue was previously discussed in BID 17462 (Microsoft MDAC RDS.Dataspace ActiveX Control Remote Code Execution Vulnerability) and is therefore being retired.
Microsoft Internet Explorer is prone to an unspecified vulnerability that results in arbitrary code execution.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the vulnerable application. This facilitates the remote compromise of affected computers.
Internet Explorer 6 is vulnerable to this issue; other versions may also be affected.
An exploit for this issue is reportedly in the wild.
Further investigation reveals this issue was previously discussed in BID 17462 (Microsoft MDAC RDS.Dataspace ActiveX Control Remote Code Execution Vulnerability) and is therefore being retired.
Exploit / POC
Retired: Microsoft Internet Explorer Unspecified Code Execution Vulnerability
The following exploit code is available; Symantec has not verified it.
CAUTION: Since the exploit code may contain malicious content, handle it carefully.
The following exploit code is available; Symantec has not verified it.
CAUTION: Since the exploit code may contain malicious content, handle it carefully.
Solution / Fix
Retired: Microsoft Internet Explorer Unspecified Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Retired: Microsoft Internet Explorer Unspecified Code Execution Vulnerability
References:
References:
- Internet Explorer Homepage (Microsoft)