Executive brief
A vulnerability exists in Microsoft Internet Explorer 4.0 that could allow an attacker to disrupt the application or execute unauthorized commands. Internet Explorer is a web browser used to access internal and external websites. If exploited, this flaw could lead to a compromise of the user's computer, potentially allowing an attacker to access sensitive data or install malicious software.
Technical details
A buffer overflow vulnerability exists in Microsoft Internet Explorer versions 4.0 and 4.0.1. The flaw is triggered when the browser processes specially crafted content, leading to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious webpage or open a malicious HTML document. Successful exploitation can result in a crash of the browser (denial of service) or the execution of arbitrary code with the privileges of the logged-in user. This is a classic memory safety issue typical of early browser implementations.
Affected products
- Microsoft Internet Explorer 4.0, 4.0.1
Timeline
- 1998-01-01: disclosed