|
Wednesday, 04 October 2006 |
|
This detection covers an exploit that currently results in Microsoft Internet Explorer crashing.
Chracterstics: This detection covers an exploit in the way than Microsoft Internet Explorer handles malformed Forms.ListBox.1 or a Forms.ComboBox.1 ActiveX control parameters, resulting in a denial of service.
As this threat utilizes script in order to carry out exploitation, V irusScan's ScriptScan component, or a gateway scanner, is required for the DAT files to offer protection from this threat. Identification is available via other DAT consuming scanners. Symptoms: Internet Explorer will likely crash upon exploitation.
This detection is sufficiently generic, such that it can cover an endless number of threats that contain the exploit code. Therefore, it is not possible to describe specific symptoms or details about system charges that can occur from this threat. However, simply seeing this detection does not mean that any exploit code was run at all as such exploit code could only run on a vulnerable system. Method of Infection: Users may be lured (such as through spam or spim) to visit a malicious site. Upon loading the web page, a vulnerable web browser will crash. Removal: All Users: Use current engine and DAT files for detection. Delete any file which contains this detection.
|