It is possible for an attacker to gain access to the path of the temporary internet files folder on a remote machine. Obtaining this information will assist in the exploitation of an existing vulnerability (Bid 1033), as well as others which together enable an attacker to execute any program on a target machine with local user privileges. There have been reports that it is still possible to exploit this vulnerability on patched versions of IE, if html file attachments to email or news messages are opened.
It is possible for an attacker to gain access to the path of the temporary internet files folder on a remote machine. Obtaining this information will assist in the exploitation of an existing vulnerability (Bid 1033), as well as others which together enable an attacker to execute any program on a target machine with local user privileges. There have been reports that it is still possible to exploit this vulnerability on patched versions of IE, if html file attachments to email or news messages are opened.