|
Microsoft Internet Explorer Plugin.OCX Load() Method Buffer Overflow Vulnerability
Microsoft Internet Explorer 'plugin.ocx' has been reported prone to a buffer overflow in some configurational circumstances. It has been reported that due to insufficient bounds checking performed on the Load() method that can be supplied by a third-party file type, an attacker may overrun a buffer and cause arbitrary code to be executed. The code is executed when a malicious URL to a third-party file is followed. Exploitation of this issue is dependant on a third-party Internet Explorer plugin being installed on the vulnerable system. Reports indicate that this vulnerability is actually a heap overflow in plugin.ocx. This issue was described in BID 7417 and is now being assigned a separate BID. Microsoft initially reported this vulnerability as a single issue within Plugin.ocx, however, there are in fact two separate issues that were fixed. The other vulnerability is described in BID 7491. |
|
|
Privacy Statement |