vendor:
Internet Explorer
by:
Trirat Puttaraksa (Kira)
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Internet Explorer
Affected Version From: Windows XP SP2 + IE6 SP1
Affected Version To: Windows 2000 SP4 + IE6
Patch Exists: YES
Related CWE: N/A
CPE: o:microsoft:windows_xp::sp2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 + IE6 SP1, Windows XP SP1 + IE6 SP1, Windows XP SP0 + IE6, Windows 2000 SP4 + IE6 SP1 and Windows 2000 SP4 + IE6
2005
Microsoft Internet Explorer VML Remote Buffer Overflow (Windows XP SP2)
This exploit is modified from Shirkdog's PoC and exploits the stack-based buffer overflow in the different manner using heap spraying technique to injection shellcode in the heap. This exploit tested on Windows XP SP2 + IE6 SP1, Windows XP SP1 + IE6 SP1, Windows XP SP0 + IE6, Windows 2000 SP4 + IE6 SP1 and Windows 2000 SP4 + IE6.
Mitigation:
Install the latest security updates and patches for the affected software.