Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

IE8 On windows 7 32 bits unspecified DoS

Go down

IE8 On windows 7 32 bits unspecified DoS Empty IE8 On windows 7 32 bits unspecified DoS

Post  andry Mon Sep 27, 2010 6:11 am

##########################################
IE8 On windows 7 32 bits unspecified DoS
Vendor URL:microsoft.com
Vendor Notify:YES Vendor confirmed:YES
EXPLOIT:Private
###########################################

A posible flaw exits in Internet explorer 8
on windows 7 32-bits ,that can cause a remote
denial of service from a malformed web page.

This issue is tiggered when IE8 try to render
Modal app prompt in conjuncion with thirds appz that
uses recurses from IE8 and try to render text inputs
it is a posible GDI text-rendering
APIs bug or or DrawText() functions involved.

When the victim visit a malformed web page, an close the 2nd
appz, this appz turns unstable and needs to close , and then
when IE8 try to restore
the tab ,it los the focus from application and it results in
a denial of service to this window , because we can't click
in any bar , in any button or do some action in this window,
ie8 aparently is frozen.

After several test this issue only is reproducible in win7 32 bits

I have a exploit or PoC for this issue , but it's
private at this time Smile

Solution:
Microsoft know that as a stability bug and they add it
for consideration in a future version to address it.

#################### €nd ##########################
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum