Skip to content
View in the app

A better way to browse. Learn more.

MSFN

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Vulnerability in IE7 Could Allow Remote Code Execution

Featured Replies

http://www.microsoft.com/technet/security/...ory/961051.mspx

"Our investigation so far has shown that these attacks are only against Windows Internet Explorer 7 on supported editions of Windows XP Service Pack 2, Windows XP Service Pack 3, Windows Server 2003 Service Pack 1, Windows Server 2003 Service Pack 2, Windows Vista, Windows Vista Service Pack 1, and Windows Server 2008."

Hmmm. IE7 / Win-XP is affected eh?

"At this time, we are aware only of attacks that attempt to use this vulnerability against Windows Internet Explorer 7."

Hmmm. Threats against IE7 are known to currently exist eh?

Oh, and just to be clear - IE7 does not run on windows-98 ?

-nuf said-


And the flaw is technically in oledb32.dll, which DOES exist on a 9x install if you have MDAC installed. So claiming invulnerability because you aren't using IE7 (IE6 and IE 5.x are vulnerable too, as is potentially any browser which would run code against this .dll in this manner) is dangerous at least.

  • Author

Microsoft has chosen to "fix" the current IE vulnerability by releasing a new version of mshtml.dll instead of fixing the real vulnerable file which is OLEDB32.DLL.

Edited by 98Guy

The exploit is use-after-free in the process doing the calling, not ole32db.dll. The fix addresses the vulnerable application, not the dll that simply exports the APIs called.

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.