Lucene search

K
saintSAINT CorporationSAINT:16C270C282D1DD8401E740D2518E56D3
HistoryDec 12, 2008 - 12:00 a.m.

Internet Explorer XML data binding memory corruption

2008-12-1200:00:00
SAINT Corporation
download.saintcorporation.com
14

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.971

Percentile

99.8%

Added: 12/12/2008
CVE: CVE-2008-4844
BID: 32721
OSVDB: 50622

Background

Internet Explorer is an HTML web browser which comes by default on Microsoft operating systems.

Problem

A data binding error allows command execution when a user loads specially crafted XML code containing nested SPAN tags, resulting in accessing of memory space of a deleted object.

Resolution

Apply one of the workarounds suggested in Microsoft Security Advisory 961051.

References

<http://www.kb.cert.org/vuls/id/493881&gt;

Limitations

Exploit works on Internet Explorer 7 and requires a user to load the exploit page.

The reliability of this exploit may depend upon the system’s memory state.

Platforms

Windows

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.971

Percentile

99.8%