This application requires Javascript for optimal performance.

MS.Shell.Handler.Remote.Code.Execution

Release Date

Feb 10, 2010

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a remote code-execution vulnerability
in IE.

It allows a remote attacker to execute arbitrary code via sending a crafted web page.

Affected Products

Microsoft Windows 2000 Service Pack 4
Windows XP Service Pack 2 and Windows XP Service Pack 3
Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems

Recommended Actions

Apply the patch, available from the vendor's website:
http://update.microsoft.com

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2010-0027

Reference/s

http://www.securityfocus.com/bid/37884 (BugTraq)
http://technet.microsoft.com/en-us/security/bulletin/MS10-007.mspx (MS-ID)

Reference: VID-18206