PT-2008-5541 · Microsoft · Internet Explorer

Carlo Di Dato

+1

·

Published

2008-12-10

·

Updated

2023-12-07

·

CVE-2008-4258

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Explorer versions 5.01 SP4 through 6 SP1
Description: A remote code execution issue exists due to improper validation of parameters during calls to navigation methods. This allows attackers to execute arbitrary code via a crafted HTML document, triggering memory corruption. An attacker could exploit this by constructing a specially crafted Web page, potentially gaining the same user rights as the logged-on user when a user views the Web page.
Recommendations: For Microsoft Internet Explorer versions 5.01 SP4 and 6 SP1, consider disabling navigation methods until a patch is available. Restrict access to specially crafted Web pages to minimize the risk of exploitation. Avoid using Internet Explorer to view untrusted Web pages until the issue is resolved.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2008-4258

Affected Products

Internet Explorer