Internet explorer 6, 7 and 8 URL Validation Vulnerability

2 views
Skip to first unread message

Lostmon lords

unread,
Jan 21, 2010, 1:54:18 PM1/21/10
to moder...@osvdb.org, bu...@securitytracker.com, vu...@securityfocus.com, vu...@secunia.com, vu...@k-otik.com, submi...@packetstormsecurity.org, ne...@securiteam.com, xfo...@iss.net, ale...@zataz.net, Vu...@frsirt.com, da...@systemsecure.org, los...@googlegroups.com
###################################
Internet explorer 6 7 and 8 URL Validation Vulnerability
Vendor :http://www.Microsoft.com
Vendor notify:YES vendor confirmed :YES
REF Bulletin:MS10-002
#########################################

A remote code execution vulnerability exists in the way that Internet
Explorer incorrectly validates input. An attacker could exploit the
vulnerability by constructing a specially crafted URL. When a user
clicks the URL, the vulnerability could allow remote code execution.
An attacker who successfully exploited this vulnerability could gain
the same user rights as the logged-on user. If a user is logged on
with administrative user rights, an attacker who successfully
exploited this vulnerability could take complete control of an
affected system. An attacker could then install programs; view,
change, or delete data; or create new accounts with full user rights.

To view this vulnerability as a standard entry in the Common
Vulnerabilities and Exposures list, see MS10-002 and CVE-2010-0027.

No more details at this time I have a PoC But At this moment it, is private.
#################€nd#############

Thnx to estrella To be mi ligth
Thnx To icar0 & sha0 from Badchecksum
Thnx To Google security Team For support
Thnx To MSRC for Support

atentamente:
Security Research & Analisys.
Lostmon (los...@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....

--
atentamente:
Lostmon (los...@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....

Reply all
Reply to author
Forward
0 new messages