PT-2010-2539 · Microsoft · Windows Server 2008+9
Chris Ries
·
Published
2010-06-08
·
Updated
2023-12-07
·
CVE-2010-0811
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer 8 Developer Tools versions in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1
Description
The issue allows remote attackers to execute arbitrary code via unknown vectors that corrupt the system state. A remote code execution vulnerability exists in the ActiveX control, Microsoft Internet Explorer 8 Developer Tools, which could be exploited by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution, potentially giving an attacker the same user rights as the logged-on user.
Recommendations
For Microsoft Internet Explorer 8 Developer Tools in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1, consider disabling the ActiveX control until a patch is available to prevent remote code execution.
As a temporary workaround, restrict access to Web pages that could potentially exploit this vulnerability to minimize the risk of exploitation.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Activex
Internet Explorer
Internet Explorer 8 Developer Tools
Windows
Windows 2000
Windows 7
Windows Server 2003
Windows Server 2008
Windows Vista
Windows Xp