>> Microsoft Windows "mhtml" Protocol Remote Buffer Overflow Vulnerability (MS06-043)
Title : Microsoft Windows "mhtml" Protocol Remote Buffer Overflow Vulnerability (MS06-043) VUPEN ID : VUPEN/ADV-2006-2088 CVE ID : CVE-2006-2766
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-06-01
Technical Description
A vulnerability has been identified in Microsoft Windows, which could be exploited by attackers to cause a denial of service or potentially take complete control of an affected system. This flaw is due to a buffer overflow error in the Microsoft Internet Messaging library "inetcomm.dll" that does not properly handle an overly long "mhtml:" URL, which could be exploited by attackers to crash an affected application (e.g. Internet Explorer or Outlook) or execute arbitrary commands by convincing a user to visit a specially crafted web page or open a malformed Internet shortcut.