This application requires Javascript for optimal performance.

MS.IE.Event.Handling.Cross.Domain.Security.Bypass

Release Date

Oct 16, 2008

Severity

medium

Impact

Security Bypass: remote attackers can bypass security checking of vulnerable systems.

Description

This indicates an attempt to exploit a security bypass vulnerability in Microsoft Internet Explorer (IE).

A vulnerability has been reported in IE that may allow an attacker to bypass security checking on a vulnerable system. This is possible because the vulnerable software fails to properly sanitize the Event Handling method used by malicious scripts. An attacker may access some objects in another domain or steal private information by tricking the user to access a malicious web page.

Affected Products

Internet Explorer 6
Internet Explorer 6 Service Pack 1
Internet Explorer 7

Recommended Actions

Refer to the vendor's web site for suggested workaround.
http://www.microsoft.com/technet/security/Bulletin/ms08-058.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2008-3473

Reference/s

http://www.microsoft.com/technet/security/Bulletin/ms08-058.mspx (MS-ID)

Reference: VID-15937