vendor:
Internet Explorer
by:
Sberry, Compaq
9,3
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: Internet Explorer
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
IE Add Favourites Stack Buffer Overflow POC
This proof-of-concept code exploits a stack buffer overflow vulnerability in Internet Explorer. The vulnerability is triggered when a user adds a maliciously crafted URL to their favorites list. The code creates a long string of characters and passes it to the vulnerable function, which causes a stack buffer overflow.
Mitigation:
Microsoft has released a patch to address this vulnerability.