Overview
Microsoft Internet Explorer (IE) fails to properly handle the createTextRange() DHTML method, possibly allowing a remote, unauthenticated attacker to execute arbitrary code.
Description
DHTML, TextRanges, and the createTextRange Method According to Microsoft: Dynamic HTML (DHTML) is built on an object model that extends the traditional static HTML document which enables Web authors to create more engaging and interactive Web pages.  | 
Impact
By convincing a user to open a specially crafted web page, a remote unauthenticated attacker can execute arbitrary code on a vulnerable system.  | 
Solution
Apply an Update  | 
Disable Active Scripting 
  | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
- http://www.microsoft.com/technet/security/advisory/917077.mspx
 - http://www.microsoft.com/technet/security/Bulletin/MS06-013.mspx
 - http://secunia.com/advisories/18680/
 - http://blogs.technet.com/msrc/archive/2006/03/22/422849.aspx
 - http://msdn.microsoft.com/workshop/author/dhtml/reference/methods/createtextrange.asp
 
Acknowledgements
This issue was reported by Andreas Sandblad of Secunia Researcha.
This document was written by Jeff Gennari.
Other Information
| CVE IDs: | CVE-2006-1359 | 
| Severity Metric: | 35.63 | 
| Date Public: | 2006-03-22 | 
| Date First Published: | 2006-03-23 | 
| Date Last Updated: | 2006-04-11 20:14 UTC | 
| Document Revision: | 46 |