CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Vulnerabilities: Microsoft Internet Explorer Multiple Vulnerabilities (Fix It) image
Security Hole
Microsoft Internet Explorer Multiple Vulnerabilities
Release Date: 2003-08-20
Critical: Extremely critical
Impact: System access
Where: From remote
Software: Microsoft Internet Explorer 5.01
Microsoft Internet Explorer 5.5
Microsoft Internet Explorer 6

CVE reference: CAN-2003-0531
CAN-2003-0532
CAN-2003-0530
CAN-2003-0344

Description:
Microsoft has issued a cumulative patch for Internet Explorer, which fixes multiple vulnerabilities. The worst vulnerability can lead to execution of arbitrary code on the client system via HTML emails or web sites.

1) A cross domain vulnerability exists in the way Internet Explorer retrieves files from the cache. This can be exploited by a malicious HTML document to execute arbitrary scripting in the My Computer Zone.

2) Internet Explorer determines whether an object is safe when it interprets the file extension specified in the Object Data tag. This allows a malicious person to specify a safe file with eg. a .html extension in Object Data, which causes Internet Explorer to interpret it as a safe file. However, when the file is retrieved by Internet Explorer the Content-Type header determines how the file will be treated. This allows an executable file like a .hta file to be treated as a safe file and be executed silently without restrictions.

Secunia has constructed a vulnerability test, which can be used to check if you are affected by this issue:
http://www.secunia.com/MS03-032/

3) The Kill Bit will be set on the Windows Reporting Tool ActiveX control BR549.DLL. This ActiveX control contains a vulnerability which could be exploited by malicious HTML documents to execute arbitrary code.

Furthermore, a language specific variant of the older object type tag buffer overflow vulnerability (MS03-020) has been identified and is fixed in this patch.

This update also fixes other minor issues.

The Object Data vulnerability is straight forward to exploit. In many ways this vulnerability is similar to MS01-020 which was exploited by notorious viruses like Nimda, Badtrans and Klez.


Solution:
The patch is available from:

http://windowsupdate.microsoft.com/

or

http://www.microsoft.com/windows/ie/downloads/critical/822925/default.asp


Reported by / credits:
1) Yu-Arai, LAC
2) Drew Copley, eEye Digital Security
3) Greg Jones, KPMG UK


Changelog:
2003-08-21: Updated critical rating and description due to detailed information from eEye.
2003-08-22: Included link to Secunia vulnerability test.


Original Advisory:
http://www.microsoft.com/technet/security/bulletin/MS03-032.asp
http://www.eeye.com/html/Research/Advisories/AD20030820.html


Related Secunia Advisories:
Microsoft MCIWNDX.OCX ActiveX Plugin Buffer Overflow
Internet Explorer AutoScan Method Cross-Site Scripting Vulnerability
Internet Explorer Custom HTTP Error Script Injection Vulnerability
Internet Explorer XML File Cross-Site Scripting Vulnerability
Internet Explorer Exposes Sensitive Information
Secunia Advisories
Posted on Monday, 25 August 2003 @ 11:15:00 UTC by phoenix22 (1291 reads)
[ Trackback ]
image

"Vulnerabilities: Microsoft Internet Explorer Multiple Vulnerabilities (Fix It)" | Login/Create an Account | 1 comment | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Microsoft Internet Explorer Multiple Vulnerabilities (Fix It) (Score: 0)
by Anonymous  on Tuesday, 26 August 2003 @ 01:38:33 UTC
Quote :
Microsoft Internet Explorer Multiple Vulnerabilities

NO SHIT.
Tells us something we don't know.

You really want to get our attention, announce the day that P.o.S. code DOESN'T have a vulnerability.


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· Microsoft
· HotScripts
· W3 Consortium
· HTML Standard
· More about Security Hole
· News by phoenix22


Most read story about Security Hole:
Windows Media Player, Spyware and Trojan

block bottom
Article Rating
spacer
Average Score: 5
Votes: 1


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer