Description: Microsoft has issued patches for Internet Explorer, which fix three vulnerabilities. One of these can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an input validation error in Internet Explorer's travel log, which is an interface used for maintaining a list of recently visited sites.
This can be exploited via a specially crafted HTML document to inject malicious URLs into the travel log, which will result in arbitrary script code being executed when the URLs are parsed.
Successful exploitation will execute the script code in context of the "MyComputer" security zone.
NOTE: This vulnerability seems to be the same as a priorly reported vulnerability. The issued patches furthermore fix two other known vulnerabilities (see "Other References" section).
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, using the Network Software Inspector.
Solution: Apply patches manually or via WindowsUpdate.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.