PT-2008-5541 · Microsoft · Internet Explorer
Carlo Di Dato
+1
·
Published
2008-12-10
·
Updated
2023-12-07
·
CVE-2008-4258
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Internet Explorer versions 5.01 SP4 through 6 SP1
Description:
A remote code execution issue exists due to improper validation of parameters during calls to navigation methods. This allows attackers to execute arbitrary code via a crafted HTML document, triggering memory corruption. An attacker could exploit this by constructing a specially crafted Web page, potentially gaining the same user rights as the logged-on user when a user views the Web page.
Recommendations:
For Microsoft Internet Explorer versions 5.01 SP4 and 6 SP1, consider disabling navigation methods until a patch is available.
Restrict access to specially crafted Web pages to minimize the risk of exploitation.
Avoid using Internet Explorer to view untrusted Web pages until the issue is resolved.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer