Secunia Advisory SA28902Microsoft Windows OLE Automation Memory Corruption
|
||||
Description
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error in the VBScript and JScript scripting engines during handling of certain script requests when using OLE (Object Linking and Embedding) Automation. This can be exploited to corrupt heap memory via specially crafted script requests. Successful exploitation allows execution of arbitrary code when a user e.g. visits a malicious website. Solution Provided and/or discovered by Technical Analysis Alternate/detailed remediation Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||
217 views | ![]() |
| Fedora update for kvirc | |
265 views | ![]() |
| Hitachi Products Two Vulnerabilities | |
502 views | ![]() |
| Wireshark Multiple Vulnerabilities | |