US-CERT Alert: Vulnerability in Microsoft Internet Explorer
March 22, 2006 -- US-CERT is aware of a vulnerability in the way Microsoft Internet Explorer handles the createTextRange() DHTML method. By persuading a user to access a specially crafted webpage, a remote, unauthenticated attacker may be able to execute arbitrary code on that user's system. This vulnerability can also be used to crash Internet Explorer.
We are aware of proof-of-concept code for this vulnerability.
More information about the reported vulnerability can be found in the following US-CERT Vulnerability Note:
* VU#876678 - Microsoft Internet Explorer createTextRange() vulnerability
Known attack vectors for this vulnerability require Active Scripting to be enabled in Internet Explorer. Disabling Active Scripting will reduce the chances of exploitation. Until an update, patch or more information becomes available, US-CERT recommends disabling Active Scripting as specified in the Securing Your Web Browser document.
We will continue to update current activity as more information becomes available.
Source: US-CERT
[ Comment, Edit or Article Submission ]