|
Microsoft Internet Explorer contains a flaw that may allow a context-dependent attacker to execute arbitrary code. The issue is due to how MSIE handles attribute removal of deleted objects. Using a specially crafted web page, if an attacker lures a victim to a web site, arbitrary code can be executed in the context of the victim's web browser (typically SYSTEM privileges).
|