MS.IE.ActiveX.Navigate.Method.Access

Last Updated DateFeb 19, 2009
Release DateDec 09, 2008
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attempt to exploit a buffer-overflow vulnerability in Microsoft Internet Explorer.

The vulnerability is located in some ActiveX controls through misuse of navigation methods. An attacker may exploit this to execute arbitrary code, or cause the program to crash.
Affected ProductsInternet Explorer 5.01 Service Pack 4 when installed on Microsoft Windows 2000 Service Pack 4
Internet Explorer 6 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4
Recommended ActionsApply patch, available from the website:
http://www.microsoft.com/technet/security/Bulletin/ms08-073.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4258
Microsoft Bulletin IDMS08-073   http://www.microsoft.com/technet/security/Bulletin/ms08-073.mspx
Reference: VID-16749