Title: Microsoft IE createTextRange() Function Arbitrary Code Execution
Info
Disclosure
Mar 22, 2006
Discovery
Feb 10, 2006
Dates
Exploit
Mar 25, 2006
Solution
Unknown
Description
Microsoft Internet Explorer contains a flaw that may allow a malicious user to execute arbitrary commands. The issue is triggered due to a memory corruption error when processing a specially crafted "createTextRange()" call associated with a "checkbox" object. It is possible that the flaw may allow attackers to remotely take complete control of an affected system resulting in a loss of integrity.
Upgrade to version 7.0 Beta 2 Preview that was released on March 20, 2006 or higher, as it has been reported to fix this vulnerability. It is also possible to mitigate the flaw by implementing the following workaround:
Disable Active Scripting support in the Internet security zone.
Note: Disabling Active Scripting may cause some Web sites to work incorrectly.