>> Microsoft Internet Explorer javaprxy.dll COM Object Vulnerability
Title : Microsoft Internet Explorer javaprxy.dll COM Object Vulnerability VUPEN ID : VUPEN/ADV-2005-0935 CVE ID : CVE-2005-2087 CWE ID : CWE-OVAL1518 - CWE-OVAL1506 - CWE-OVAL793
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-07-01
Technical Description
A vulnerability was identified in Microsoft Internet Explorer, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to an error in the "javaprxy.dll" COM Object when instantiated in Internet Explorer via a specially crafted HTML tag, which could be exploited via a malicious Web page to compromise and take complete control of a vulnerable system.
Proof of concept Exploit :
http://www.frsirt.com/exploits/20050702.iejavaprxyexploit.pl.php
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.