Overview
Microsoft Internet Explorer (IE) fails to properly handle the createTextRange() DHTML method, possibly allowing a remote, unauthenticated attacker to execute arbitrary code.
Description
DHTML, TextRanges, and the createTextRange Method According to Microsoft: Dynamic HTML (DHTML) is built on an object model that extends the traditional static HTML document which enables Web authors to create more engaging and interactive Web pages. |
Impact
By convincing a user to open a specially crafted web page, a remote unauthenticated attacker can execute arbitrary code on a vulnerable system. |
Solution
Apply an Update |
Disable Active Scripting
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.microsoft.com/technet/security/advisory/917077.mspx
- http://www.microsoft.com/technet/security/Bulletin/MS06-013.mspx
- http://secunia.com/advisories/18680/
- http://blogs.technet.com/msrc/archive/2006/03/22/422849.aspx
- http://msdn.microsoft.com/workshop/author/dhtml/reference/methods/createtextrange.asp
Acknowledgements
This issue was reported by Andreas Sandblad of Secunia Researcha.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-1359 |
Severity Metric: | 35.63 |
Date Public: | 2006-03-22 |
Date First Published: | 2006-03-23 |
Date Last Updated: | 2006-04-11 20:14 UTC |
Document Revision: | 46 |