OSVDB ID: 15465

Title: Microsoft IE DHTML Object Memory Corruption Code Execution

Info

Disclosure

Apr 12, 2005

Discovery

Oct 25, 2004

Dates

Exploit

Apr 12, 2005

Solution

Dec 04, 2005

Description

Windows contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when certain DHTML methods are used, leading to a race condition when one thread reads data from memory that has either been overwritten by another thread or has not yet been initialized by another thread. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation, Race Condition
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public, Exploit Commercial
Disclosure: OSVDB Verified, Vendor Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation

Windows

2000 SP3
2000 SP4
XP SP1
XP SP2
XP 64-Bit SP1
XP 64-Bit 2003
98
98 SE
ME

Windows Server

2003
2003 for Itanium

References

Credit

  • Berend-Jan Wever - skylinededup.tudelft.nl -


Direct URL: http://osvdb.org/15465