Microsoft Internet Explorer HTML Objects Remote Code Execution Vulnerability
BID:32586
Info
Microsoft Internet Explorer HTML Objects Remote Code Execution Vulnerability
| Bugtraq ID: | 32586 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-4259 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2008 12:00AM |
| Updated: | Jan 08 2009 06:42PM |
| Credit: | Brett Moore working with TippingPoint and the Zero Day Initiative |
| Vulnerable: |
Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Peri Workstation 0 Nortel Networks Peri Application 0 Nortel Networks MPS Speech Server 6.0 Nortel Networks Media Processing Svr 500 Rel 3.0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Nortel Networks Media Processing Svr 100 0 Nortel Networks Media Processing Server Nortel Networks Contact Center Multimedia Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Manager Nortel Networks Contact Center Express Nortel Networks Contact Center - Quality Monitoring 0 Nortel Networks Contact Center - Contact Recording 0 Nortel Networks Contact Center Microsoft Internet Explorer 7.0 HP Storage Management Appliance 2.1 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer HTML Objects Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Exploit / POC
Microsoft Internet Explorer HTML Objects Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Internet Explorer HTML Objects Remote Code Execution Vulnerability
Solution:
The vendor released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Internet Explorer 7.0
Solution:
The vendor released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Internet Explorer 7.0
-
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB958215)
http://www.microsoft.com/downloads/details.aspx?familyid=9cdd4f9e-c578 -405c-af9e-628f2d77fdf4 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 64-bit Itanium Edition (K
http://www.microsoft.com/downloads/details.aspx?familyid=3811030d-5958 -4b91-b5b8-20587dc7c4d6 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB958215)
http://www.microsoft.com/downloads/details.aspx?familyid=7c36f92c-d8a0 -4b70-b85f-83588a0299a0 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP (KB958215)
http://www.microsoft.com/downloads/details.aspx?familyid=1b582695-b3cc -4c65-bc4b-d673c9a6d82a -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB958215)
http://www.microsoft.com/downloads/details.aspx?familyid=107cf54b-29d4 -4c54-b091-2b5b3ffbf49d -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB958215)
http://www.microsoft.com/downloads/details.aspx?familyid=45a0de3c-c7d1 -4314-a456-1f7428b7c90a -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB958215)
http://www.microsoft.com/downloads/details.aspx?familyid=405b28db-47d7 -4d6b-90e6-834c0a409323 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB958215)
http://www.microsoft.com/downloads/details.aspx?familyid=3f62030a-9ce2 -4c92-b948-143a6881921e -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB958215)
http://www.microsoft.com/downloads/details.aspx?familyid=d8800493-fba4 -41f8-bde5-a53eeaf89d54 -
Microsoft Cumulative Security Update for Internet Explorer in Windows Server 2008 64-bit Itanium Edition (KB95
http://www.microsoft.com/downloads/details.aspx?familyid=f0d4f321-941e -4da7-958f-582c75542ee8
References
Microsoft Internet Explorer HTML Objects Remote Code Execution Vulnerability
References:
References:
- ISVA-081209.1 - IE Webdav Request Parsing Heap Corruption Vulnerability (Insomnia Security)
- Microsoft Internet Explorer Homepage (Microsoft)
- Insomnia : ISVA-081209.1 - IE Webdav Request Parsing Heap Corruption Vulnerabili ("Brett Moore"
) - ZDI-08-087: Microsoft Internet Explorer Webdav Request Parsing Heap Corruption V ([email protected])
- Microsoft Internet Explorer Webdav Request Parsing Heap Corruption Vulnerability (Zero Day Initiative)
- Microsoft Security Bulletin MS08-073 (Microsoft)
- Nortel Response to Microsoft Security Bulletin MS08-073 (Nortel Networks)