Overview
Microsoft Internet Explorer contains a vulnerability that may allow unintended information disclosure or remote code execution due to a flaw in handling Channel Definition Format (CDF) files.
Description
From the Microsoft Channel Definition Format description: Channel Definition Format (CDF) files can be used to organize a set of related Web pages into a logical hierarchy. A channel is a Web site described by a Channel Definition Format (CDF) file. The CDF file defines a hierarchy of the pages that are included in the channel. Besides defining the resources in the channel, the CDF file also specifies how each item will be used or displayed, and when the channel should be updated. For more information about CDF files, see the product documentation. |
Impact
A remote attacker may be able to execute arbitrary code or access otherwise restricted information by crafting a malicious web page, then convincing a user to visit it by clicking on a link or email. The code would execute with the privileges of the user running Internet Explorer. |
Solution
Apply an update |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.microsoft.com/technet/security/Bulletin/MS05-014.mspx
- http://www.cert.org/advisories/CA-2000-02.html#impact
- http://www.cert.org/tech_tips/malicious_code_FAQ.html#ie56
- http://support.microsoft.com/?kbid=833633
- http://support.microsoft.com/?kbid=315933
- http://support.microsoft.com/?kbid=240797
Acknowledgements
Thanks to the Microsoft Corporation for reporting this vulnerability.
This document was written by Ken MacInnis based primarily on information provided by the Microsoft Corporation.
Other Information
CVE IDs: | CVE-2005-0056 |
Severity Metric: | 21.00 |
Date Public: | 2005-02-08 |
Date First Published: | 2005-02-08 |
Date Last Updated: | 2005-02-09 17:02 UTC |
Document Revision: | 13 |