Windows 2003 (tsuserex.dll) COM Object Instantiation Vulnerability
: Windows 2003 (tsuserex.dll) COM Object Instantiation Vulnerability
: Windows 2003 (tsuserex.dll) COM Object Instantiation Vulnerability
Advisory ID:
XSec-06-06
Advisory Name:
Windows 2003 (tsuserex.dll) COM Object Instantiation Vulnerability
Release Date:
08/18/2006
Tested on:
Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN
Affected version:
Windows Server 2003 + Internet Explorer 6.0
Author:
nop http://www.xsec.org
Overview:
A vulnerability has been found in Internet Explorer 6.0 on \
Microsoft Windows 2003. When Internet Explorer tries to \
instantiate the tsuserex.dll (Terminal Services) COM object \
as an ActiveX control, it may corrupt system memory in such \
a way that an attacker may DoS and possibly could execute \
arbitrary code.
Exploit:
=============== tsuserex.dll.htm start ===============
=============== tsuserex.dll.htm end =================
Link:
http://www.xsec.org/index.php?module=Releases&act=view&type=1&id=14
About XSec:
We are redhat.