PornoSecurity: sexy vulns, porno sploits and the like

MS Internet Explorer XML Parsing Remote Exploit

Posted on 2008-12-10 17:31:19 in PornoSecurity

BugThis was found by somebody while it is being exploited in the wild. ISC claims it is a 0day and it is not patched by the MS december bulletin but I can't reproduce the bug on a system patched this morning...

 

Internet Explorer 6 and 7 seems to be vulnerable and I managed to achieve code execution on Windows XP SP3.  As usual you can find the exploit here.

Nick