Microsoft IE contains a flaw that may allow a malicious user to gain the same user rights as the logged in user. The issue is triggered when IE parses certain strings in CSS. It is possible for a malacious person to construct a specially crafted website which could remotely execute code on the visitor's computer.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation,
Other
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified,
Vendor Verified
Solution
Upgrade to IE version 6 or 7, as it has been reported to fix this vulnerability. Additionally, the vendor has released the MS07-045 cummulative security update to address this issue. Otherwise, users may opt to apply the following workaround: do not browse untrusted websites.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.