Threat Monitor
« Back to list
Troj.Exploit.W32.CrashIe.b
| Aliases: | |
|---|
| Pattern: | 200908211330 |
|---|
| Threat Type | Propagation Methods | Systems Affected | Risk Level |
| | | - Windows NT
- Windows XP
- Windows 2000
- Windows 95/98/ME
- MS-DOS
- Other
| |
This malicious program exploits vulnerability CVE-2009-2433.
Microsoft Internet Explorer is prone to a remote denial-of-service vulnerability. The vulnerability is caused due to an error in the AddFavorite method in Microsoft Internet Explorer. The vulnerability can result in a stack-based buffer overflow via a long URL in the first argument. Successful exploits may allow the remote attacker to crash Microsoft Internet Explorer, cause a denial of service (application crash), and possibly have other unspecified impacts on the attacked system.
The sample contains a specially crafted SWF file. The sample dropped a Trojan to the system when it executed.
Affected Versions: Microsoft Internet Explorer 8.0
Microsoft Internet Explorer 7.0
Back to Top