This application requires Javascript for optimal performance.

MS.IE.HTML.File.Arbitrary.Execution

Release Date

Jan 05, 2012

Severity

medium

Impact

System compromise: An attacker can execute arbitrary program on infected systems.

Description

This indicates an attack attempt against an Arbitrary File Execution vulnerability in Internet Explorer.

The vulnerability is due to the vulnerable application's insufficient security checking on HTML header content. An attacker can create a specially crafted web page which contains malicious executable programs to exploit this vulnerability. When a victim is tricked into visiting such a web page, the attacker program can be downloaded to and executed on the victim machine.

Affected Products

Microsoft Internet Explorer version 6.0

Recommended Actions

Disable automatic file download.
Apply appropriate patches or upgrade the system to the latest non-vulnerable version.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2001-0727

Reference/s

http://www.securityfocus.com/bid/3578 (BugTraq)
http://technet.microsoft.com/en-us/security/bulletin/MS01-058.mspx (MS-ID)

Reference: VID-30655