Microsoft Internet Explorer "window()" Code Execution Vulnerability
Title : Microsoft Internet Explorer "window()" Code Execution Vulnerability Advisory ID : FrSIRT/ADV-2005-2509 CVE ID : CVE-2005-1790
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-11-21
A critical vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to a memory corruption error when processing malformed HTML pages containing specially crafted calls to JavaScript "window()" objects and "onload" events, which could be exploited remote attackers to take complete control of an affected system by convincing a user to visit a malicious Web page [...] References
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.