MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
Welcome to MSMVPS.COM Sign in | Help
in Search

Harry Waldron - Microsoft MVP Blog

Security News and Best Practices for corporate and home users

MS05-020: DHTML Proof of Concept Exploit Developed

MS05-020: DHTML Proof of Concept Exploit Developed
http://isc.sans.org/diary.php?date=2005-04-12

MS05-020 - Cumulative Security Update for Internet Explorer. This aggregate patch addresses several vulnerabilities in Internet Explorer that could lead to remote code execution:

* DHTML Object Memory Corruption Vulnerability (CAN-2005-0553)
* URL Parsing Memory Corruption Vulnerability (CAN-2005-0554)
* Content Advisor Memory Corruption Vulnerability (CAN-2005-0555)

Special note: A proof-of-concept exploit for this vulnerability is already publicly available from FrSIRT. The availability of the exploit is likely to increase the severity of this patch for most organizations.

French Security Incident Response Team
http://www.frsirt.com/english/

Microsoft Internet Explorer DHTML Object handling Exploit (MS05-020) - Please be careful as actual POC code is present in this link 
http://www.frsirt.com/exploits/20050412.InternetExploiter2.php

Only published comments... Apr 13 2005, 09:46 PM by harry

Comments

 

TrackBack said:

April 14, 2005 4:18 AM
 

TrackBack said:

April 14, 2005 4:18 AM

Leave a Comment

(required) 
(optional)
(required) 
Submit
Powered by Community Server (Commercial Edition), by Telligent Systems