Intrusion Prevention

MS.IE.Language.Pack.Installation.Code.Execution

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Internet Explorer. Some user interaction is required.
The specific flaw exists in routines responsible for the on-demand installation of Internet Explorer language packs. A race condition may occur when a web page contains several pieces of content written in a language not currently supported by any of the installed language packs. In many cases, this race condition results in exploitable memory corruption that can be used to execute arbitrary code.

Affected Products

Microsoft Internet Explorer 5.01, 6, and 7.

Impact

System Compromise, remote code execution.

Recommended Actions

Please go to http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx for an appropriate software update.

CVE References

CVE-2007-3027

Other References

ZDI-07-037