Release DateDec 12, 2006 |
Severitycritical |
ImpactArbitrary code execution |
DescriptionA remote code execution vulnerability exists in the way Internet Explorer interprets certain DHTML script function calls to incorrectly created elements. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could potentially allow remote code execution if a user viewed the Web page. An attacker who successfully exploited this vulnerability could take complete control of an affected system. |
Affected ProductsInternet Explorer 6 |
Recommended ActionsMicrosoft has issued an update to correct this vulnerability. More details can be found at: http://www.microsoft.com/technet/security/Bulletin/MS06-072.mspx |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2006-5581 |
Reference/shttp://technet.microsoft.com/en-us/security/bulletin/ms06-072.mspx (MS-ID)http://www.zerodayinitiative.com/advisories/ZDI-06-048.html http://www.frsirt.com/english/advisories/2006/4966 (FrSIRT) http://www.securityfocus.com/bid/21546 (BugTraq) |