| Last Updated Date | Nov 10, 2009 |
| Release Date | Oct 10, 2007 |
| Severity | High |
| Impact | System Compromise: Remote attackers can gain control of vulnerable systems. |
| Description | This indicates an attack attempt against a URL spoofing vulnerability in Microsoft Internet Explorer 7.
The vulnerability is caused by an error when the vulnerable software handles document.open() call. It allows a remote attacker to prevent users from leaving a site, spoof the address or launch phishing attack. |
| Affected Products | Microsoft Internet Explorer 7.0 |
| Recommended Actions | Apply patch, available from the website: http://www.microsoft.com/technet/security/Bulletin/ms07-057.mspx |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3826
|
| Microsoft Bulletin ID | MS07-057 http://www.microsoft.com/technet/security/Bulletin/MS07-057.mspx |
| Reference/s | http://www.securityfocus.com/bid/24911 (BugTraq)
|