vendor:
Internet Explorer
by:
Computer Terrorism (UK) & Darkeagle of Unl0ck Research Team
N/A
CVSS
N/A
Remote System Access
119
CWE
Product Name: Internet Explorer
Affected Version From: Microsoft Internet Explorer 6.x
Affected Version To: Microsoft Internet Explorer 7 Beta 2
Patch Exists: NO
Related CWE: N/A
CPE: a:microsoft:internet_explorer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2006
Internet Explorer “createTextRang” Download Shellcoded Exploit
This exploit is a remote system access vulnerability in Microsoft Internet Explorer 6.x & 7 Beta 2. It is caused by a buffer overflow in the createTextRange() function. The exploit uses a shellcode to download a malicious file from a remote server and execute it on the victim's machine. The exploit is unpatched and has a critical severity.
Mitigation:
Microsoft has not released a patch for this vulnerability yet. Users should avoid using Internet Explorer 6.x & 7 Beta 2 until a patch is released.