mailing list archives
Re: .MHT Buffer Overflow in Internet Explorer
From: "Thor Larholm" <thor () pivx com>
Date: Sun, 26 Jan 2003 00:23:16 +0100
From: "jelmer" <jelmer () kuperus xs4all nl>
I believe from ie6 SP1 on IE doesn't open any mht files directly from the
from the local filesystem it still works though.
That's the funny thing, IE6 SP1 still allows opening MHT files directly from
the web in the Internet Zone, so this is remotely exploitable on websites.
Since MHT files are opened automatically, just like certain other media
files, you can also open an MHT file automatically through an email message
in the Restricted Zone.
PivX Solutions, LLC - Senior Security Researcher