Immunity, Inc.
Name wp_ms10_018
CVE CVE-2010-0267
Exploit Pack White_Phosphorus
DescriptionInternet Explorer 6 Tabular Data Control ActiveX Remote Overflow (ms10-018)
NotesVENDOR: Microsoft
Notes:
This is a client-side exploit - so use it via clientd or httpserver, or run the module and send the created file to the target user.

If using through clientD disable the jsrecon functionality.

VersionsAffected: XP SP1/SP2/SP3 IE 6
Repeatability: Unlimited
MSADV: MS10-018
References: http://www.zerodayinitiative.com/advisories/ZDI-10-034
http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx
CVE Url: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0267
Date public: 2010-04-02
CVE: CVE-2010-0267
CVSS: 10.0

Learn more about the CANVAS Exploit Pack here: White_Phosphorus