vendor:
Internet Exploiter 3
by:
Berend-Jan Wever
N/A
CVSS
N/A
Stack Overflow
119
CWE
Product Name: Internet Exploiter 3
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2003-2004
Internet Exploiter 3 v0.2 ANI stackoverflow PoC exploit
This is a proof of concept exploit for a stack overflow vulnerability in Internet Exploiter 3 v0.2. The exploit takes advantage of a vulnerability in the .ANI file format to overwrite the stack and potentially execute arbitrary code. The exploit works by placing a specially crafted .ANI file in the BODY of an HTML document. The vulnerability was discovered by Yuji Ukai of eEye Digital Security. Microsoft has released a patch for this vulnerability, which can be found at the provided link.
Mitigation:
Apply the patch provided by Microsoft.