Advisory ID: XSec-06-06 Advisory Name: Windows 2003 (tsuserex.dll) COM Object Instantiation Vulnerability Release Date: 08/18/2006 Tested on: Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN Affected version: Windows Server 2003 + Internet Explorer 6.0 Author: nop http://www.xsec.org Overview: A vulnerability has been found in Internet Explorer 6.0 on \ Microsoft Windows 2003. When Internet Explorer tries to \ instantiate the tsuserex.dll (Terminal Services) COM object \ as an ActiveX control, it may corrupt system memory in such \ a way that an attacker may DoS and possibly could execute \ arbitrary code. Exploit: =============== tsuserex.dll.htm start ================ =============== tsuserex.dll.htm end ================== Link: http://www.xsec.org/index.php?module=Releases&act=view&type=1&id=14 About XSec: We are redhat.