This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Exploit For Ms04-038...released

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?date=2005-03-09
Updated March 9th 2005 21:38 UTC
"We've seen a recently released exploit for a buffer overflow in CSS parsing code under versions of IE (6.0 SP1 and earlier) that was patched in October of '04 in MS04-038. More information on the vulnerability can be found at:

- http://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0842

…we would recommend that if you're aren't currently patched… get patched."

>>> http://www.microsoft.com/technet/security/…n/ms04-038.mspx
"Cumulative Security Update for Internet Explorer (834707)…
Severity Rating: Critical…"

:ph34r:
(Opps…) :oops:

- http://isc.sans.org/diary.php?date=2005-03-09
Updated March 10th 2005 02:10 UTC
"…Ah… Nate wrote in to point out that the MS04-038 patch has been superceded by other patches, specifically MS05-008 and MS05-014…"

- http://www.microsoft.com/technet/security/…n/ms05-008.mspx

- http://www.microsoft.com/technet/security/…n/ms05-014.mspx


(As my Canuck friends say "Some fun, eh?…" …keeping track of all these holes…Still, if you're not patched, get there.)

:blink: