MS.IE.Same.ID.Property.Code.Execution

description-logoDescription

This indicates an attack attempt against a Code Execution vulnerability in Microsoft Internet Explorer.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application. An attacker can trick an unsuspecting user into visiting a malicious webpage and execute arbitrary script code within the context of the target's browser.

affected-products-logoAffected Products

Internet Explorer 8 for Windows XP Service Pack 3
Internet Explorer 8 for Windows XP Professional x64 Edition Service Pack 2
Internet Explorer 8 for Windows Server 2003 Service Pack 2
Internet Explorer 8 for Windows Server 2003 x64 Edition Service Pack 2
Internet Explorer 8 in Windows Vista Service Pack 2
Internet Explorer 8 in Windows Vista x64 Edition Service Pack 2
Internet Explorer 8 in Windows Server 2008 for 32-bit Systems Service Pack 2
Internet Explorer 8 in Windows Server 2008 for x64-based Systems Service Pack 2
Internet Explorer 8 in Windows 7 for 32-bit Systems
Internet Explorer 8 in Windows 7 for 32-bit Systems Service Pack 1
Internet Explorer 8 in Windows 7 for x64-based Systems
Internet Explorer 8 in Windows 7 for x64-based Systems Service Pack 1
Internet Explorer 8 in Windows Server 2008 R2 for x64-based Systems
Internet Explorer 8 in Windows Server 2008 R2 for x64-based Systems Service Pack 1
Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Systems
Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary script code within the context of the target user's browser.

recomended-action-logoRecommended Actions

Refer to the vendor's web site for suggested workaround.
http://technet.microsoft.com/en-us/security/bulletin/ms12-037.mspx

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)