MS.IE.DHTML.Function.Remote.Code

NameMS.IE.DHTML.Function.Remote.Code.Execution
Release DateJun 11, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against an arbitrary code-execution vulnerability in Microsoft Internet Explorer.

The vulnerability is caused by improper handling of DHTML functions. It may allow a remote attacker to execute arbitrary code via sending a crafted web page.
Affected ProductsMicrosoft Internet Explorer 6
Recommended ActionsCurrently we are not aware of any patches supplied by the vendor for this issue.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1141
Microsoft Bulletin IDMS09-019   http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx
Reference: VID-17483