Virus Encyclopedia
Welcome to the Virus Encyclopedia of Panda Security.
Exploit/iFrame | |
Threat Level Damage Distribution |
At a glance
 |
| Common name: | Exploit/iFrame |
| Technical name: | Exploit/iFrame |
| Threat level: | Low |
| Alias: | Exploit,, iFrame |
| Type: | Hacking Tool |
| Effects: | It allows files attached to email messages to be automatically run in Outlook Express. |
| Affected platforms:
| MS-DOS; Windows XP/2000/NT/ME/98/95 |
| First detected on: | April 23, 2002 |
| Detection updated on: | June 17, 2010 |
| Statistics | No |
Proactive protection: | Yes, using TruPrevent Technologies
|
Brief Description | |
Exploit/iFrame is code written in the HTML language, which is included in the body of a message in order to exploit a vulnerability in Internet Explorer. This vulnerability affects Internet Explorer 5.01 and 5.5 SP-1, and allows files attached to email messages to be automatically run when the message is viewed through Outlook Preview Pane. It is exploited by worms like Klez, Nimda, Badtrans, Frethem, etc., in order to be run automatically through Outlook Preview Pane. For more information on this vulnerability and on the corresponding security patch, visit the Microsoft website. |
Tech details
Effects |
Exploit/iFrame is HTML code that is included in the body of an email message. This code allows a virus to exploit a vulnerability that affects Internet Explorer 5.01 and 5.5 SP-1, which allows files attached to email messages to be automatically run when the message is viewed through Outlook's Preview Pane. It is exploited by worms like Klez, Nimda, Badtrans, Frethem, etc., in order to be run automatically. The only way to know if you are exposed to this vulnerability is to find out the installed version of affected programs in order to install the corresponding security patches. |
Further Details
Panda Antivirus detects and eliminates the code of Exploit/iFrame that allows worms to exploit this Internet Explorer vulnerability to automatically run themselves.