找回密码
 注册账户
查看: 261|回复: 0

Microsoft IE Remote Code Execution Exploit (0day) – Critical

[复制链接]
admin 发表于 2012-3-21 22:35:10 | 显示全部楼层 |阅读模式
FrSIRT have identified a critical vulnerability with Internet Explorer 6 for Windows XP SP1 and SP2.
The problem could be exploited by remote attackers to execute arbitrary commands. The issue is due to a memory corruption error when instantiating the "Msdds.dll" (Microsoft Design Tools Diagram Surface) object as an ActiveX control, which could be exploited by an attacker to take complete control of an affected system via a specially crafted Web page.Unfortunately for users of Internet Explorer 6 there is 0day Exploit Code readily available for would be hackers to create web pages. This is un-usual and brings into question whether FrSIRT were taking decent measures to ensure Microsoft were aware of this threat.

According to a Microsoft Spokesperson, "Microsoft is aggressively investigating new public reports of a possible vulnerability in Internet Explorer. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. Microsoft is concerned that this new report of a vulnerability in Internet Explorer was not disclosed responsibly, potentially putting computer users at risk."

We will keep you updated on Microsoft’s investigations and whether they plan to release a patch for this flaw soon.

News source: Neowin
您需要登录后才可以回帖 登录 | 注册账户

本版积分规则

存档|黑屋|手机|网络实验室 本站服务器由美国合租以及IDCLayer国际数据提供!!!

GMT+8, 2026-6-9 02:54 , Processed in 0.009570 second(s), 5 queries , Gzip On, Redis On.

Powered by Discuz! X3.5

© 2001-2025 Discuz! Team.

快速回复 返回顶部 返回列表