Microsoft Security Bulletin: IE Patch
MS TechNet | at | by Mike
Who should read this bulletin: Customers using Microsoft Internet Explorer.
Impact of vulnerability: Run code of attacker's choice.
This patch, when installed, eliminates all known security vulnerabilities affecting Internet Explorer 5.5 and 6.0. In addition to eliminating all previously discussed vulnerabilities affecting these versions, it also eliminates three new ones:
- A vulnerability involving the handling of downloads that can lead to automatic code execution.
- A newly discovered variant of the the "Frame Domain Verification" vulnerability discussed in Microsoft Security Bulletin MS01-015.
- A vulnerability involving the display of file names in the File Download dialogue box.