Microsoft Internet Explorer contains a flaw that may allow a malicious user to execute arbitrary commands. The issue is triggered due to a memory corruption error when processing a specially crafted "createTextRange()" call associated with a "checkbox" object. It is possible that the flaw may allow attackers to remotely take complete control of an affected system resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
Solution
Upgrade to version 7.0 Beta 2 Preview that was released on March 20, 2006 or higher, as it has been reported to fix this vulnerability. It is also possible to mitigate the flaw by implementing the following workaround: Disable Active Scripting support in the Internet security zone. Note: Disabling Active Scripting may cause some Web sites to work incorrectly.