Intrusion Prevention

MS.IE.cloneNode.nodeValue.Memory.Corruption

Description

This indicates detection of an attempt to exploit a remote code execution vulnerability in Microsoft Internet Explorer.
The vulnerability is a result of the way that Internet Explorer accesses an object that has not been correctly initialized or that has been deleted. A reference counting bug in MSHTML.DLL can be exploited to allow code of an attacker's choice to run in the context of the currently logged in user.

Affected Products

Microsoft Internet Explorer 6
Microsoft Internet Explorer 7

Impact

System compromise.

Recommended Actions

Microsoft has issued an update to correct this vulnerability. More details can be found at:
http://www.microsoft.com/technet/security/bulletin/ms07-069.mspx

CVE References

CVE-2007-3903