[原文]Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file type such as .xml, .doc, .py, .cdf, .css, .pdf, or .ppt, and using ADODB.Connection and ADODB.recordset to write to a .hta file that is interpreted in the Local Zone by HTML Help.
Microsoft IE HTML Help Drag and Drop Arbitrary Code Injection
Remote / Network Access
Loss of Integrity
Windows contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to inadequate Local Machine Lockdown policies, in which an attacker can take advantage of HTML Help (hh.exe) to execute arbitrary code.
Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.