HTTP: Microsoft Internet Explorer IESHIMS.DLL Insecure Library Loading

This signature detects attempts to exploit a known remote code execution vulnerability in Microsoft Internet Explorer. It is due to a design weakness in loading Dynamically Linked Libraries. Remote attackers can exploit this by enticing target users to download a malicious "IESHIMS.DLL" file. A successful attack can result in loading the attacker-controlled library and execution of arbitrary code with the privileges of the logged-in user. If a user is logged-on with administrative user rights, an attacker can take complete control of the affected system.

Extended Description

Microsoft Internet Explorer is prone to vulnerability that lets attackers execute arbitrary code. An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.

Affected Products

Avaya messaging_application_server,Avaya meeting_exchange

References

BugTraq: 46159

CVE: CVE-2011-0038

Short Name
HTTP:IESHIMS-DLL-HIJACK
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2011-0038 Explorer IESHIMS.DLL Insecure Internet Library Loading Microsoft bid:46159
Release Date
05/17/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Avaya

Microsoft

CVSS Score

9.3

Found a potential security threat?