module

MS12-037 Microsoft Internet Explorer Fixed Table Col Span Heap Overflow

Disclosed
2012-06-12
Created
2018-05-30

Description

This module exploits a heap overflow vulnerability in Internet Explorer caused
by an incorrect handling of the span attribute for col elements from a fixed table,
when they are modified dynamically by javascript code.

Authors

Alexandre Pelletier
mr_me steventhomasseeley@gmail.com
binjo
sinn3r sinn3r@metasploit.com
juan vazquez juan.vazquez@metasploit.com

Platform

Windows

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use exploit/windows/browser/ms12_037_ie_colspan
msf exploit(ms12_037_ie_colspan) > show targets
...targets...
msf exploit(ms12_037_ie_colspan) > set TARGET < target-id >
msf exploit(ms12_037_ie_colspan) > show options
...show and set options...
msf exploit(ms12_037_ie_colspan) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.