Microsoft IE contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to an invalid flag reference within Internet Explorer. It can allow remote code execution
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public,
Exploit Commercial
Disclosure:
Discovered in the Wild
Solution
OSVDB is not aware of a solution for this vulnerability. The usggested workaround are to override the Web site CSS with a user-defined style sheet and enable Data Execution Prevention (DEP) for Internet Explorer 7