Overview
Microsoft Internet Explorer fails to properly handle directories with CLSID extensions. This may allow an attacker to bypass the warning dialog that Internet Explorer should display before executing downloaded code.
Description
CLSID According to Microsoft MSDN, A CLSID is a "globally unique identifier (GUID) associated with an OLE class object." |
Impact
By convincing a user to access a specially crafted web page with Internet Explorer, an attacker may be able to execute arbitrary code with the privileges of the user. |
Solution
Apply an update |
Do not follow unsolicited links
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- [<a href="http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20060627/3d930eda/PLEBO-2006.06.16-IE_ONE_MINOR_ONE_MAJOR.obj">http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20060627/3d930eda/ PLEBO-2006.06.16-IE_ONE_MINOR_ONE_MAJOR.obj</a>]
- http://secunia.com/advisories/20825/
- http://isc.sans.org/diary.php?storyid=1448&rss
- http://windowssdk.msdn.microsoft.com/en-us/library/ms691424.aspx
- http://www.microsoft.com/technet/security/bulletin/MS04-024.mspx
Acknowledgements
This vulnerability was publicly disclosed by Plebo Aesdi Nael.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2006-3281 |
Severity Metric: | 10.80 |
Date Public: | 2006-06-27 |
Date First Published: | 2006-06-29 |
Date Last Updated: | 2006-08-08 19:07 UTC |
Document Revision: | 12 |