Overview
Microsoft Internet Explorer contains a flaw in DHTML method handling which may allow a remote attacker to execute arbitrary code.
Description
The DHTML method handling in Internet Explorer fails to perform proper bounds checking. This vulnerability may allow data to be written outside the boundary of a buffer, creating a heap overflow condition that may allow remote attackers to execute arbitrary code. To exploit this vulnerability, the attacker would craft a malicious web page and convince the user to visit it, either by clicking on a link in a web page or in an email message. |
Impact
A remote attacker may be able to execute arbitrary code with the privileges of the user running Internet Explorer. |
Solution
Apply an update Microsoft Windows users should use Windows Update to automatically obtain the correct fixes, or apply the relevant patches outlined in Microsoft Security Bulletin MS05-014, described in Microsoft Knowledge Base Article 867282. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.microsoft.com/technet/security/Bulletin/MS05-014.mspx
- http://www.cert.org/advisories/CA-2000-02.html#impact
- http://www.cert.org/tech_tips/malicious_code_FAQ.html#ie56
- http://support.microsoft.com/?kbid=833633
- http://support.microsoft.com/?kbid=315933
- http://support.microsoft.com/?kbid=240797
- http://activex.microsoft.com/activex/controls/dhtmled/dhtmled.asp
- http://msdn.microsoft.com/archive/default.asp?url=/archive/en-us/dnaredcom/html/cncpt.asp
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnmshtml/html/mshtmleditplatf.asp
- http://secunia.com/advisories/11165/
Acknowledgements
Thanks to the Microsoft Corporation for reporting this vulnerability, who in turn credit Andreas Sandblad of Secunia for reporting the information.
This document was written by Ken MacInnis based primarily on information provided by the Microsoft Corporation.
Other Information
CVE IDs: | CVE-2005-0055 |
Severity Metric: | 31.88 |
Date Public: | 2005-02-08 |
Date First Published: | 2005-02-08 |
Date Last Updated: | 2005-08-22 13:13 UTC |
Document Revision: | 13 |