CVE-2009-0341: Buffer Overflow
Published Jan 29, 2009
·Updated
The shell32 module in Microsoft Internet Explorer 7.0 on Windows XP SP3 might allow remote attackers to execute arbitrary code via a long VALUE attribute in an INPUT element, possibly related to a stack consumption vulnerability.
Affected Software
4 affected components
Microsoft Windows XP=sp3
Microsoft Internet Explorer=7
All of the following
Microsoft Windows XP=sp3
Microsoft Internet Explorer=7
Event History
Jan 29, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·07:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which environments should be prioritized for assessment?
Prioritize systems running Microsoft Internet Explorer 7.0 on Windows XP SP3. The issue is associated with the shell32 module in that environment.
2
What would an attacker need to attempt exploitation?
The attack can be conducted remotely without authentication. It involves a long VALUE attribute in an HTML INPUT element.
3
What is the potential impact if exploitation succeeds?
Successful exploitation might allow arbitrary code execution. The reported severity vector indicates potential compromise of confidentiality, integrity, and availability.