Internet Explorer COM object instantiation vulnerability
Added: 02/24/2006CVE: CVE-2005-1990
BID: 14511
OSVDB: 18612
Background
Windows operating systems use the Component Object Model (COM) to allow various program components to be run within different applications.Problem
Improper instantiation of certain COM objects as ActiveX controls by Internet Explorer leads to a buffer overflow which can result in command execution.Resolution
Apply the patch referenced in Microsoft Security Bulletin 05-038.References
http://www.microsoft.com/technet/security/Bulletin/MS05-038.mspxLimitations
This exploit requires a user to follow a link to the exploit from a vulnerable host. Exploit works on Internet Explorer 6.0.Platforms
Windows 2000Windows XP
Windows Server 2003
Back to exploit index