AplusWebMaster
Topic Starter
FYI…
- http://news.com.com/2102-1002_3-6052396.ht…g=st.util.print
last modified Wed Mar 22 06:28:23 PST 2006
"Microsoft is investigating a security flaw that could let an attacker gain control over a vulnerable Windows computer, the company said Tuesday. The flaw was reported to the company earlier this month by Jeffrey van der Stad, a 25-year-old Dutch programmer. The problem is related to the way the browser processes so-called HTA files, Microsoft said in an e-mailed statement. HTA files are associated with Web applications… "With this vulnerability it is possible to run an HTA file without the user's permission," he wrote… This is the second IE flaw within a week that Microsoft has said it is investigating and may issue a patch for. On Monday the company said it was looking into a bug that could cause the browser to crash. Microsoft's next scheduled Patch Tuesday is on April 11."
IEv6 Unspecified Remote HTA Execution Vuln
- http://www.securityfocus.com/bid/17181/info
Vulnerable:
Microsoft Internet Explorer 6.0 SP2
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
- http://jeffrey.vanderstad.net/grasshopper/
"Q: Can you publish more details? Can you share it with me?
A: No can do. Setting this thing free will do more harm than good. It's not in the open yet, I'd like to keep it that way…"
(…The "right way" to do it. Kudos, Jeff.)

- http://news.com.com/2102-1002_3-6052396.ht…g=st.util.print
last modified Wed Mar 22 06:28:23 PST 2006
"Microsoft is investigating a security flaw that could let an attacker gain control over a vulnerable Windows computer, the company said Tuesday. The flaw was reported to the company earlier this month by Jeffrey van der Stad, a 25-year-old Dutch programmer. The problem is related to the way the browser processes so-called HTA files, Microsoft said in an e-mailed statement. HTA files are associated with Web applications… "With this vulnerability it is possible to run an HTA file without the user's permission," he wrote… This is the second IE flaw within a week that Microsoft has said it is investigating and may issue a patch for. On Monday the company said it was looking into a bug that could cause the browser to crash. Microsoft's next scheduled Patch Tuesday is on April 11."
IEv6 Unspecified Remote HTA Execution Vuln
- http://www.securityfocus.com/bid/17181/info
Vulnerable:
Microsoft Internet Explorer 6.0 SP2
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
- http://jeffrey.vanderstad.net/grasshopper/
"Q: Can you publish more details? Can you share it with me?
A: No can do. Setting this thing free will do more harm than good. It's not in the open yet, I'd like to keep it that way…"
(…The "right way" to do it. Kudos, Jeff.)