MS.IE.Same.ID.Property.Code.Execution
Description
This indicates an attack attempt against a Code Execution vulnerability in Microsoft Internet Explorer.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application. An attacker can trick an unsuspecting user into visiting a malicious webpage and execute arbitrary script code within the context of the target's browser.
Affected Products
Internet Explorer 8 for Windows XP Service Pack 3
Internet Explorer 8 for Windows XP Professional x64 Edition Service Pack 2
Internet Explorer 8 for Windows Server 2003 Service Pack 2
Internet Explorer 8 for Windows Server 2003 x64 Edition Service Pack 2
Internet Explorer 8 in Windows Vista Service Pack 2
Internet Explorer 8 in Windows Vista x64 Edition Service Pack 2
Internet Explorer 8 in Windows Server 2008 for 32-bit Systems Service Pack 2
Internet Explorer 8 in Windows Server 2008 for x64-based Systems Service Pack 2
Internet Explorer 8 in Windows 7 for 32-bit Systems
Internet Explorer 8 in Windows 7 for 32-bit Systems Service Pack 1
Internet Explorer 8 in Windows 7 for x64-based Systems
Internet Explorer 8 in Windows 7 for x64-based Systems Service Pack 1
Internet Explorer 8 in Windows Server 2008 R2 for x64-based Systems
Internet Explorer 8 in Windows Server 2008 R2 for x64-based Systems Service Pack 1
Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Systems
Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
Impact
System Compromise: Remote attackers can execute arbitrary script code within the context of the target user's browser.
Recommended Actions
Refer to the vendor's web site for suggested workaround.
http://technet.microsoft.com/en-us/security/bulletin/ms12-037.mspx
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |