PT-2008-1734 · Microsoft · Internet Explorer
Published
2008-02-12
·
Updated
2018-10-12
·
CVE-2008-0078
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 5.01, 6 SP1, 6 SP2, and 7
Description
The issue allows remote attackers to execute arbitrary code via a crafted image. A remote code execution vulnerability exists in the way Internet Explorer handles argument validation in image processing. An attacker could exploit the vulnerability by constructing a specially crafted Web page, which could allow remote code execution when a user views the Web page. An attacker who successfully exploited this issue could gain the same user rights as the logged on user.
Recommendations
For Microsoft Internet Explorer version 5.01, update to a newer version to mitigate the risk.
For Microsoft Internet Explorer version 6 SP1, update to a newer version to mitigate the risk.
For Microsoft Internet Explorer version 6 SP2, update to a newer version to mitigate the risk.
For Microsoft Internet Explorer version 7, update to a newer version to mitigate the risk.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer