Description: This security update resolves a publicly disclosed vulnerability. The vulnerability could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The security update addresses the vulnerability by modifying the way Internet Explorer validates data binding parameters and handles the error resulting in the exploitable condition.
Update type: Critical
Release date: December 17, 2008
Applies to: All versions
Knowledge base: http://support.microsoft.com/kb/960714
- Pointer Reference Memory Corruption Vulnerability – CVE-2008-4844