PT-2008-5542 · Microsoft · Internet Explorer
Brett Moore
·
Published
2008-12-10
·
Updated
2023-12-07
·
CVE-2008-4259
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Internet Explorer version 7
Description:
A remote code execution issue exists due to attempts to access uninitialized memory in certain situations. An attacker could exploit this by constructing a specially crafted Web page. When a user views the Web page, it could allow remote code execution, potentially giving the attacker the same user rights as the logged-on user.
Recommendations:
For Microsoft Internet Explorer version 7, consider avoiding the use of WebDAV requests for files with long names until a patch is available. As a temporary workaround, restrict access to crafted HTML documents that could trigger memory corruption.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer