search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Microsoft Internet Explorer contains an integer overflow in the processing of bitmap files

Vulnerability Note VU#266926

Original Release Date: 2004-07-30 | Last Revised: 2004-07-31

Overview

A vulnerability in Microsoft Internet Explorer could allow a remote attacker to execute arbitrary code on a vulnerable system.

Description

Microsoft Internet Explorer (IE) is a web browser. An integer overflow vulnerability has been discovered in the way that Internet Explorer processes bitmap image files. This vulnerability could allow a remote attacker to execute arbitrary code on a vulnerable system by introducing a specially crafted bitmap file.

Impact

A remote attacker may be able to execute arbitrary code on a vulnerable system by introducing a specially crafted bitmap file. This malicious bitmap image may be introduced to the system via a malicious web page, HTML email, or an email attachment.

Solution

Apply Patch

Apply a patch as described in Microsoft Security Bulletin MS04-025.

Vendor Information

266926
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to gta@hush.com for reporting this vulnerability.

This document was written by Chad R Dougherty.

Other Information

CVE IDs: CVE-2004-0566
Severity Metric: 56.11
Date Public: 2004-02-15
Date First Published: 2004-07-30
Date Last Updated: 2004-07-31 01:07 UTC
Document Revision: 10

Sponsored by CISA.