Jump to content

Vulnerability in IE7 Could Allow Remote Code Execution


98Guy

Recommended Posts

http://www.microsoft.com/technet/security/...ory/961051.mspx

"Our investigation so far has shown that these attacks are only against Windows Internet Explorer 7 on supported editions of Windows XP Service Pack 2, Windows XP Service Pack 3, Windows Server 2003 Service Pack 1, Windows Server 2003 Service Pack 2, Windows Vista, Windows Vista Service Pack 1, and Windows Server 2008."

Hmmm. IE7 / Win-XP is affected eh?

"At this time, we are aware only of attacks that attempt to use this vulnerability against Windows Internet Explorer 7."

Hmmm. Threats against IE7 are known to currently exist eh?

Oh, and just to be clear - IE7 does not run on windows-98 ?

-nuf said-

Link to comment
Share on other sites


And the flaw is technically in oledb32.dll, which DOES exist on a 9x install if you have MDAC installed. So claiming invulnerability because you aren't using IE7 (IE6 and IE 5.x are vulnerable too, as is potentially any browser which would run code against this .dll in this manner) is dangerous at least.

Link to comment
Share on other sites

Microsoft has chosen to "fix" the current IE vulnerability by releasing a new version of mshtml.dll instead of fixing the real vulnerable file which is OLEDB32.DLL.

Edited by 98Guy
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...