Microsoft Internet Explorer CSS Memory Corruption Remote Code Execution Vulnerability
BID:33628
Info
Microsoft Internet Explorer CSS Memory Corruption Remote Code Execution Vulnerability
| Bugtraq ID: | 33628 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-0076 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2009 12:00AM |
| Updated: | Feb 17 2009 03:27PM |
| Credit: | Sam Thomas working with TippingPoint and the Zero Day Initiative |
| Vulnerable: |
Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service MPS 100 0 Nortel Networks Multimedia Comm Mas 0 Nortel Networks Enterprise VoIP TM-CS1000 Microsoft Internet Explorer 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CSS Memory Corruption Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Exploit / POC
Microsoft Internet Explorer CSS Memory Corruption Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Internet Explorer CSS Memory Corruption Remote Code Execution Vulnerability
Solution:
The vendor released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Internet Explorer 7.0
Solution:
The vendor released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Internet Explorer 7.0
-
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB961260)
http://www.microsoft.com/downloads/details.aspx?familyid=e52aa1fd-e694 -4322-b3ff-6abc1b4a16fe -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 64-bit Itanium Edition (K
http://www.microsoft.com/downloads/details.aspx?familyid=5ce78797-d1c0 -40d4-84e1-1004389833be -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB961260)
http://www.microsoft.com/downloads/details.aspx?familyid=edbf1566-b96b -4c7d-98fe-b15f8e766792 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP (KB961260)
http://www.microsoft.com/downloads/details.aspx?familyid=8cd902ec-e018 -4b61-80f9-825d973f998e -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB961260)
http://www.microsoft.com/downloads/details.aspx?familyid=dd3e2236-9cc0 -478e-a46c-981ef685c0e3 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB961260)
http://www.microsoft.com/downloads/details.aspx?familyid=2491dbf2-7cd3 -44f1-bfad-77e6f760a25c -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB961260)
http://www.microsoft.com/downloads/details.aspx?familyid=794373cc-2dce -4ef5-af50-7804c622c230 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB961260)
http://www.microsoft.com/downloads/details.aspx?familyid=5f9fa4b6-85a4 -43bc-b84f-6bd847799650 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB961260)
http://www.microsoft.com/downloads/details.aspx?familyid=e9a8c94b-b9d2 -4d64-855f-b5f02ce3dfb5 -
Microsoft Cumulative Security Update for Internet Explorer in Windows Server 2008 64-bit Itanium Edition (KB96
http://www.microsoft.com/downloads/details.aspx?familyid=11985325-4b33 -4077-82cf-6afc7a71c510
References
Microsoft Internet Explorer CSS Memory Corruption Remote Code Execution Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)
- ZDI-09-012: Microsoft Internet Explorer Malformed CSS Memory Corruption (ZDI Disclosures
) - 2009009324: Nortel Response to Microsoft Security Bulletin MS09-002 (Nortel Networks)
- Microsoft Internet Explorer Malformed CSS Memory Corruption Vulnerability (Zero Day Initiative)
- Microsoft Security Bulletin MS09-002 (Microsoft)