Threat Monitor
Troj.Downloader.HTML.Agent.sa
| Aliase: | |
|---|---|
| Pattern: | 201009181330 |
| Threat Typ | Verbreitung | Betroffene Systeme | Gefährlichkeit |
|---|---|---|---|
|
|
|
|
The vulnerability is caused by an error in the CTimeoutEventList::InsertIntoTimeoutList() function of the mshtml.dll library. The vulnerable function will return heap addresses and a counter instead of a timer ID. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to obtain sensitive information.
Affected: Microsoft Internet Explorer 8.0


