PT-2008-1734 · Microsoft · Internet Explorer

Published

2008-02-12

·

Updated

2018-10-12

·

CVE-2008-0078

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 5.01, 6 SP1, 6 SP2, and 7
Description The issue allows remote attackers to execute arbitrary code via a crafted image. A remote code execution vulnerability exists in the way Internet Explorer handles argument validation in image processing. An attacker could exploit the vulnerability by constructing a specially crafted Web page, which could allow remote code execution when a user views the Web page. An attacker who successfully exploited this issue could gain the same user rights as the logged on user.
Recommendations For Microsoft Internet Explorer version 5.01, update to a newer version to mitigate the risk. For Microsoft Internet Explorer version 6 SP1, update to a newer version to mitigate the risk. For Microsoft Internet Explorer version 6 SP2, update to a newer version to mitigate the risk. For Microsoft Internet Explorer version 7, update to a newer version to mitigate the risk.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0078

Affected Products

Internet Explorer