Skip to main content

Microsoft Windows MHTML Mime-Formatted Request Vulnerability

Last Update Date: 15 Jun 2011 14:02 Release Date: 15 Jun 2011 5307 Views

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

An information disclosure vulnerability exists in the way that MHTML interprets MIME-formatted requests for content that are embedded in an HTML document. Similar to server-side cross-site scripting (XSS) vulnerabilities, it is possible under certain conditions for this vulnerability to allow an attacker to inject a client-side script in the response to a web request run in the context of the user's instance of Internet Explorer.


Impact

  • Information Disclosure

System / Technologies affected

  • Windows XP
  • Windows Server 2003
  • Windows Vista
  • Windows Server 2008
  • Windows 7
  • Windows Server 2008 R2

 


Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

 


Vulnerability Identifier

 


Source

 


Related Link