>> Microsoft XML Parser and XML Core Services Multiple Vulnerabilities (MS06-061)
Title : Microsoft XML Parser and XML Core Services Multiple Vulnerabilities (MS06-061) VUPEN ID : VUPEN/ADV-2006-3980 CVE ID : CVE-2006-4685 - CVE-2006-4686
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-10
Technical Description
Multiple vulnerabilities have been identified in Microsoft Windows, which could be exploited by attackers to take complete control of an affected system or bypass security restrictions.
The first flaw is due to an error in the way the XMLHTTP control applies IE security settings to a redirected data stream returned in response to HTTP requests, which could be exploited by malicious people to read cookies and data from another security zone or domain in Internet Explorer.
The second flaw is due to a buffer overflow error in the Extensible Stylesheet Language Transformations (XSLT) control when processing malformed data, which could be exploited by remote attackers to execute arbitrary commands via a specially crafted web page.
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.