PT-2006-4595 · Microsoft · Windows Xp Sp2+4
Hdm
·
Publicado
2006-07-19
·
Atualizado
2021-07-23
·
CVE-2006-3730
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer 6 on Windows XP SP2
Description
The issue is caused by an integer overflow when a 0x7fffffff argument is passed to the setSlice method on a WebViewFolderIcon ActiveX object, leading to an invalid memory copy. This could allow remote attackers to cause a denial of service or execute arbitrary code. A remote code execution vulnerability exists in Windows Shell due to improper validation of input parameters when invoked by the WebViewFolderIcon ActiveX control. An attacker could exploit this by hosting a specially crafted web site or sending a specially crafted e-mail message, potentially taking complete control of an affected system.
Recommendations
For Microsoft Internet Explorer 6 on Windows XP SP2, update to a newer version to mitigate the risk.
As a temporary workaround, consider disabling the WebViewFolderIcon ActiveX control until a patch is available.
Restrict access to web sites that could potentially exploit this vulnerability to minimize the risk of exploitation.
Exploit
Correção
RCE
DoS
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Internet Explorer 6
Webviewfoldericon Activex
Windows
Windows Shell
Windows Xp Sp2