* Technical Description *
A vulnerability has been identified in Microsoft Internet Explorer, which potentially could be exploited by remote attackers to execute arbitrary commands. This flaw is due to an unspecified memory corruption error when processing malformed HTML pages, which could be exploited remote attackers to take complete control of an affected system via specially crafted Web pages. No further details have been disclosed.
* Affected Products *
Microsoft Internet Explorer 6 for Microsoft Windows XP SP2
Microsoft Internet Explorer 6 SP1 on Microsoft Windows XP SP1
Microsoft Internet Explorer 5.01 SP4 on Microsoft Windows 2000 SP4
Microsoft Internet Explorer 6 SP1 on Microsoft Windows 2000 SP4
Microsoft Internet Explorer 6 for Microsoft Windows Server 2003
Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 SP1
Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 for Itanium-based Systems
Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition
Microsoft Internet Explorer 6 for Microsoft Windows XP Professional x64 Edition
* Solution *
No official supplied patch for this issue.
* References *
http://www.frsirt.com/english/advisories/2005/1571http://www.security-protocols.com/modules.php?name=News&file=article&sid=2891