1. Research - Home |
  2. Advisories |
  3. Alerts |
  4. Tools |
  5. Papers |
  6. Services |
  7. Contact |
  8. About
Home > Alerts
Alerts
Alerts | Zero-Day Tracker | EEYEZD-20061104

Common Name:
XMLHTTP 4.0 ActiveX

Date Disclosed:
11/4/2006

Date Patched:
11/14/2006

Vendor:
Microsoft

Application:
Internet Explorer 5.01
Internet Explorer 6

Description:
A buffer overflow exists within the msxml4.dll ActiveX object which may be exploited by attackers to execute arbitrary code on a remote system by a specially-crafted website.

Severity:
High

Code Execution:
Yes

Impact:
Arbitrary code execution under the context of the logged in user
An ActiveX remote code execution vulnerability has a very high impact since the source of the malicious payload can be any site on the Internet. An even more critical problem is generated when clients are administrators on their local hosts, which would run the malicious payload with Administrator credentials.

Mitigation:
The best form of mitigation is available by kill-bitting the CLSIDs for the WMI Object Broker ActiveX Control (88d969c5-f192-11d4-a65f-0040963251e5) following the directions of KB240797.

Protection:
Patch:
Microsoft Patch - MS06-071

Links:
CVE-2006-5745
First Public PoC Code Disclosure (Launches Calc.exe)
Microsoft Security Advisory (927892)

Status:
11/14/2006: Patched - MS06-071