vendor:
Internet Explorer
by:
Ahmed Obied
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 7.0.5730.13 with OWC10.dll or OWC11.dll installed
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
Internet Explorer OWC Remote Code Execution
This exploit allows remote attackers to execute arbitrary code on a vulnerable system using Internet Explorer with OWC installed. The payload used in this exploit is a Metasploit shellcode that executes the calc.exe calculator. The payload is converted to UTF-16 encoding before being sent to the target system.
Mitigation:
To mitigate this vulnerability, users should ensure that they are using the latest version of Internet Explorer and that OWC is not installed.