Executive brief
A critical vulnerability exists in the core HTML library used by several Microsoft Windows components, including Internet Explorer and Outlook Express. This flaw allows an attacker to potentially take full control of a user's computer if they view a specially crafted web page or email. This could lead to the theft of sensitive data, installation of malware, or complete system failure.
Technical details
A buffer overflow vulnerability exists in the HTML rendering library (Mshtml.dll) shared by Microsoft Internet Explorer 4.0, Outlook Express, and Windows Explorer. The flaw is triggered when processing specially crafted URLs using the 'res:' local resource protocol. An attacker can exploit this by enticing a user to visit a malicious website or open a formatted email, leading to arbitrary code execution with the privileges of the logged-in user. This is a remote attack vector requiring no prior authentication. While the vulnerability is legacy, it represented a significant risk to the integrity and confidentiality of Windows systems at the time of discovery.
Affected products
- Microsoft Internet Explorer 4.0
- Microsoft Outlook Express
- Microsoft Windows Explorer
Timeline
- 1997-11-01: disclosed: Initial publication date