<< Back
CVE Number Vulnerability Product Severity Date
MS09-002 Cumulative Security Update for Internet Explorer (961260) Windows Internet Critical 11-02-2009

Technical Information

Brief overview of the risk:
This security update resolves two privately reported vulnerabilities. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.
Detailed Information on the risk:

A remote code execution vulnerability exists in the way Internet Explorer handles Cascading Style Sheets (CSS). An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged on user.


Further information on this exploit is available at : MS09-002

Affected Software

Windows Internet Explorer 7