This application requires Javascript for optimal performance.

MS.IE.ADODB.Recordset.Filter.Remote.DoS

Release Date

Dec 30, 2011

Severity

medium

Impact

Denial of Service: Remote attackers can crash vulnerable systems.

Description

This indicates an attempt to exploit a Denial of Service vulnerability in Microsoft Internet Explorer

The vulnerability is a result of a NULL pointer dereference error in the Microsoft Data Access ActiveX "msado15.dll" object. It can be triggered by a specially crafted "ADODB.Recordset Filter Property". It can be exploited by attackers to crash a vulnerable browser by tricking a user into visiting a malicious web page.

Affected Products

Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0

Recommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-3354

Reference/s

http://www.securityfocus.com/bid/18773 (BugTraq)

Reference: VID-30459