PT-2008-1733 · Microsoft · Internet Explorer
Hyy
·
Publicado
2008-02-12
·
Atualizado
2024-02-03
·
CVE-2008-0077
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 6 SP1 through 7
Description
A use-after-free issue allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, such as the
by property of an animateMotion SVG element. This can be exploited through a specially crafted Web page, potentially allowing an attacker to gain the same user rights as the logged on user.Recommendations
For Microsoft Internet Explorer versions 6 SP1 through 7, consider disabling the use of SVG elements, specifically the
animateMotion element, until a patch is available. Restrict access to Web pages that could potentially exploit this issue to minimize the risk of remote code execution.Correção
RCE
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Internet Explorer