Lucene search

K
zdiSam Thomas of eshu.co.ukZDI-09-012
HistoryFeb 10, 2009 - 12:00 a.m.

Microsoft Internet Explorer Malformed CSS Memory Corruption Vulnerability

2009-02-1000:00:00
Sam Thomas of eshu.co.uk
www.zerodayinitiative.com
19

EPSS

0.812

Percentile

98.4%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists when processing, in XHTML strict mode, a CSS stylesheet containing a specific combination of style directives one of which must be a ‘zoom’. The fault in processing results in a memory corruption vulnerability which can be leveraged to execute arbitrary code under the context of the current user.