Microsoft Windows Explorer contains a flaw that may allow a malicious user to insert arbitrary scripts. The issue is due to an input validation error in the Web View library (webvw.dll). By tricking a user to select a malicious word document with a specially crafted author name in Windows Explorer, an attacker can execute arbitrary HTML and scripts with the logon user's privileges.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
Solution
Microsoft has released a patch to address this vulnerability. It is alspossible to correct the flaw by implementing the following workaround: disable the Web View by going to: Tools -> Folder Options -> Select 'Use Windows classic folders'