Threat Monitor
Troj.Downloader.HTML.Agent.sa
| Aliases: | |
|---|---|
| Pattern: | 201009181330 |
| Threat Type | Propagation Methods | Systems Affected | Risk Level |
|---|---|---|---|
|
|
|
|
Microsoft Internet Explorer is prone to a remote information disclosure vulnerability.
The vulnerability is caused by an error in the CTimeoutEventList::InsertIntoTimeoutList() function of the mshtml.dll library. The vulnerable function will return heap addresses and a counter instead of a timer ID. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to obtain sensitive information.
Affected: Microsoft Internet Explorer 8.0
The vulnerability is caused by an error in the CTimeoutEventList::InsertIntoTimeoutList() function of the mshtml.dll library. The vulnerable function will return heap addresses and a counter instead of a timer ID. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to obtain sensitive information.
Affected: Microsoft Internet Explorer 8.0


