vendor:
Internet Explorer
by:
Jelmer Kuperus
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 5.01
Affected Version To: Internet Explorer 6.0
Patch Exists: YES
Related CWE: CVE-2006-4868
CPE: a:microsoft:internet_explorer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2006
Microsoft Internet Explorer MHTML Protocol Handler Buffer Overflow Vulnerability
A buffer overflow vulnerability exists in Microsoft Internet Explorer due to a boundary error when handling MHTML protocol requests. This issue is due to a failure of the application to properly bounds check user-supplied input before copying it into an insufficiently sized memory buffer. This issue may be exploited by enticing a user to open a maliciously crafted MHTML protocol request. Successful exploitation of this issue may allow an attacker to execute arbitrary code in the context of the user running the application.
Mitigation:
Microsoft has released a patch to address this issue. Users are advised to apply the appropriate patch.