Microsoft Internet Explorer Baseline Tag Rendering Remote Code Execution Vulnerability
BID:37895
Info
Microsoft Internet Explorer Baseline Tag Rendering Remote Code Execution Vulnerability
| Bugtraq ID: | 37895 |
| Class: | Unknown |
| CVE: |
CVE-2010-0246 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 21 2010 12:00AM |
| Updated: | Jan 29 2010 08:01PM |
| Credit: | Sam Thomas of eshu.co.uk working with TippingPoint and the Zero Day Initiative |
| Vulnerable: |
Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri CTI 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Self-Service CDD 0 Nortel Networks Self Service - CDD 0 Nortel Networks Peri Workstation 0 Nortel Networks Peri Application 0 Nortel Networks Media Processing Svr 500 Rel 3.0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Nortel Networks Media Processing Svr 100 0 Nortel Networks Media Processing Server Nortel Networks Contact Center Multimedia & Outbound 7.0 Nortel Networks Contact Center Multimedia & Outbound 6.0 Nortel Networks Contact Center Express Nortel Networks Contact Center Administration CCMA 7.0 Nortel Networks Contact Center Administration CCMA 6.0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 600r Nortel Networks CallPilot 202i Nortel Networks CallPilot 201i Nortel Networks CallPilot 1005r Microsoft Internet Explorer 8 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Baseline Tag Rendering Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the computer. Failed attacks may cause denial-of-service conditions.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the computer. Failed attacks may cause denial-of-service conditions.
Exploit / POC
Microsoft Internet Explorer Baseline Tag Rendering Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer Baseline Tag Rendering Remote Code Execution Vulnerability
References:
References:
- Avaya Enterprise (Fomerly Nortel Enterprise) Response to Microsoft Security Bull (Nortel Networks)
- Microsoft Internet Explorer Homepage (Microsoft)
- ZDI-10-012: Microsoft Internet Explorer Baseline Tag Rendering Remote Code Execu (Zero Day Initiative)
- ZDI-10-012: Microsoft Internet Explorer Baseline Tag Rendering Remote Code Execu (ZDI Disclosures
) - ASA-2010-018 MS10-002 Cumulative Security Update for Internet Explorer (978207) (Avaya)
- Microsoft Security Bulletin MS10-002 (Microsoft)