CVE-2008-4844
CVE-2008-4844
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
Affected products
n/a · n/apublic PoCs found — 5
cve_referencewww.exploit-db.com/exploits/7477unverifiedcve_referencewww.exploit-db.com/exploits/7583unverifiedcve_referencewww.exploit-db.com/exploits/7410unverifiedexploitdbwww.exploit-db.com/exploits/16583unverifiedcve_referencewww.exploit-db.com/exploits/7403unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://blogs.msdn.com/sdl/archive/2008/12/18/ms08-078-and-the-sdl.aspxhttp://code.google.com/p/inception-h2hc/http://isc.sans.org/diary.html?storyid=5458http://marc.info/?l=bugtraq&m=123015308222620&w=2https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-078http://secunia.com/advisories/33089https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6007https://www.exploit-db.com/exploits/7403https://www.exploit-db.com/exploits/7410https://www.exploit-db.com/exploits/7477https://www.exploit-db.com/exploits/7583http://www.avertlabs.com/research/blog/index.php/2008/12/09/yet-another-unpatched-drive-by-exploit-found-on-the-web/