Overview
Certain versions of Microsoft Internet Explorer (IE) that support double-byte character sets (DBCS) contain a buffer overflow vulnerability in the Type attribute of the OBJECT element. A remote attacker could execute arbitrary code with the privileges of the user running IE.
Description
Microsoft Security Bulletin MS03-032 and SNS Advisory No.68 describe a buffer overflow vulnerability in the Type attribute of the OBJECT element. This vulnerability only affects double-byte character set versions of IE (e.g. Japanese) and may be related to VU#679556/CAN-2003-0344/MS030-020. |
Impact
By convincing a victim to view an HTML document (web site, HTML email message), a remote attacker could execute arbitrary code with the privileges of the victim. |
Solution
Apply patch Apply 822925 or a more recent cumulative patch for IE. See Microsoft Security Bulletin MS03-032. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Microsoft credits LAC/SNS for reporting this vulnerability. Information used in this document came from LAC/SNS and Microsoft.
This document was written by Art Manion.
Other Information
CVE IDs: | CVE-2003-0701 |
CERT Advisory: | CA-2003-22 |
Severity Metric: | 7.09 |
Date Public: | 2003-08-20 |
Date First Published: | 2003-08-26 |
Date Last Updated: | 2005-08-11 20:50 UTC |
Document Revision: | 17 |