Microsoft Internet Explorer Property Method Remote Code Execution Vulnerability
BID:23769
Info
Microsoft Internet Explorer Property Method Remote Code Execution Vulnerability
| Bugtraq ID: | 23769 |
| Class: | Unknown |
| CVE: |
CVE-2007-0945 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2007 12:00AM |
| Updated: | May 17 2007 09:38PM |
| Credit: | This issue was disclosed in the referenced vendor advisory. |
| Vulnerable: |
Nortel Networks Contact Center Web Client Nortel Networks Contact Center Multimedia Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Manager Nortel Networks Contact Center Express Nortel Networks Contact Center Administration 0 Nortel Networks Contact Center - Symposium Agent 0 Nortel Networks Contact Center Nortel Networks Centrex IP Client Manager Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 7.0.5730 .11 Microsoft Internet Explorer 7.0 beta3 Microsoft Internet Explorer 7.0 beta2 Microsoft Internet Explorer 7.0 beta1 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 SP2 - do not use Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 HP Storage Management Appliance 2.1 Avaya Web Messenger 0 Avaya VPNmanagerTM Console 0 Avaya Visual Vector Client 0 Avaya Visual Messenger TM 0 Avaya Unified Messenger (r) 0 Avaya Unified Communications Center S3400 Avaya Unified Communication Center Avaya Speech Access 0 Avaya Outbound Contact Management 0 Avaya Operational Analyst 0 Avaya OctelDesignerTM 0 Avaya OctelAccess(r) Server 0 Avaya Network Reporting 0 Avaya Modular Messaging (MSS) 2.0 SP4 Avaya Modular Messaging (MSS) 2.0 Avaya Modular Messaging (MSS) 1.1 Avaya Modular Messaging (MAS) 3.0 Avaya Modular Messaging (MAS) Avaya Modular Messaging S3400 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server 0 Avaya IP Softphone 0 Avaya IP Agent 0 Avaya Interaction Center - Voice Quick Start 0 Avaya Interaction Center 0 Avaya Integrated Management 2.1 Avaya Integrated Management Avaya Enterprise Management 0 Avaya CVLAN Avaya Contact Center Express 0 Avaya Computer Telephony 0 Avaya CMS Supervisor 0 Avaya CIE 1.0 Avaya Basic Call Management System Reporting Desktop server Avaya Basic Call Management System Reporting Desktop 0 Avaya Agent Access 0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Property Method Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to remote code-execution vulnerability.
A remote attacker can exploit this issue to execute arbitrary code in the context of the user running the vulnerable application.
Microsoft Internet Explorer is prone to remote code-execution vulnerability.
A remote attacker can exploit this issue to execute arbitrary code in the context of the user running the vulnerable application.
Exploit / POC
Microsoft Internet Explorer Property Method Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Microsoft Internet Explorer Property Method Remote Code Execution Vulnerability
Solution:
Microsoft has released security bulletin MS07-027 with fixes to address this issue. Please see the referenced bulletin for information on obtaining fixes.
Microsoft Internet Explorer 7.0 beta1
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0 SP2 - do not use
Solution:
Microsoft has released security bulletin MS07-027 with fixes to address this issue. Please see the referenced bulletin for information on obtaining fixes.
Microsoft Internet Explorer 7.0 beta1
-
Microsoft Cumulative Update for Internet Explorer 7 for Windows Server 2003 (KB931768)
Windows Internet Explorer 7 for Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=0F173D60-6FD0 -4C92-BB2A-A7A78707E35F&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 for Windows Server 2003 64-bit Itanium Edition (KB931768)
Windows Internet Explorer 7 for Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?familyid=1944BCFA-B0BC -4BD5-9089-A618EA43EA49&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB931768)
ows Internet Explorer 7 for Windows Server 2003 x64 Edition Service Pack 1 and Windows Server 2003 x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=404A48A2-5765 -4AFA-94BF-E97212AA14EF&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 for Windows XP Service Pack 2 (KB931768)
Windows Internet Explorer 7 for Windows XP Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=7A778D93-9D85 -4217-8CC0-5C494D954CA0&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 for Windows XP x64 Edition (KB931768)
Windows Internet Explorer 7 for Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=29938ED4-F8BB -4793-897C-966BA7F4830C&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 in Windows Vista (KB931768)
Windows Internet Explorer 7 in Windows Vista
http://www.microsoft.com/downloads/details.aspx?familyid=0C65FAD3-BAAE -46C4-B453-84CF28B15F50&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 in Windows Vista x64 Edition (KB931768)
Windows Internet Explorer 7 in Windows Vista x64 Edition
http://www.microsoft.com/downloads/details.aspx?familyid=74AFEA3D-79DF -4B64-BF30-B8E5C55CAB2B&displaylang=en
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Update for Internet Explorer 6 SP1 (KB931768)
Microsoft Internet Explorer 6 Service Pack 1 when installed on Windows 2000 Service Pack 4
http://www.microsoft.com/downloads/details.aspx?familyid=03FC8E0C-DEC5 -48D1-9A34-3B639F185F7D&displaylang=en
Microsoft Internet Explorer 6.0 SP2 - do not use
-
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 (KB931768)
Microsoft Internet Explorer 6 for Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=D249089D-BB8E -4B86-AB8E-18C52844ACB2&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB931768)
Microsoft Internet Explorer 6 for Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?familyid=D52C0AFD-CC3A -4A5C-B91B-E006D497BC26&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 x64 Edition (KB931768)
Microsoft Internet Explorer 6 for Windows Server 2003 x64 Edition Service Pack 1 and Windows Server 2003 x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=94B83BDD-2BD1 -43E4-BABF-68135D253293&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows XP Service Pack 2 (KB931768)
Microsoft Internet Explorer 6 for Windows XP Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=EFC6BE04-0D6B -4639-8485-DA1525F6BC52&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows XP x64 Edition (KB931768)
Microsoft Internet Explorer 6 for Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=A077BE20-C379 -4386-B478-80197A4A4ABC&displaylang=en
References
Microsoft Internet Explorer Property Method Remote Code Execution Vulnerability
References:
References: