Serious bug found in Internet Explorer with XP SP2

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 0
Joined: Sun Apr 25, 2004 1:05 pm

Serious bug found in Internet Explorer with XP SP2

Post by Tami »

Secunia Advisory: SA12889
Release Date: 2004-10-20

Critical: Highly critical
Impact: Security Bypass
System access
Where: From remote
Solution Status: Unpatched

Software: Microsoft Internet Explorer 6

Description:
http-equiv has discovered two vulnerabilities in Internet Explorer, which can be exploited by malicious people to compromise a user's system, link to local resources, and bypass a security feature in Microsoft Windows XP SP2.

1) Insufficient validation of drag and drop events from the "Internet" zone to local resources for valid images or media files with embedded HTML code. This can be exploited by e.g. a malicious web site to plant arbitrary HTML documents on a user's system, which may allow execution of arbitrary script code in the "Local Computer" zone.

This vulnerability is related to: SA12321

NOTE: Microsoft Windows XP SP2 does not allow Active Scripting in the "Local Computer" zone.

2) A security zone restriction error, where an embedded HTML Help control on e.g. a malicious web site references a specially crafted index (.hhk) file, can execute local HTML documents.

NOTE: This will also bypass the "Local Computer" zone lockdown security feature in SP2.

The two vulnerabilities in combination with an inappropriate behaviour where the ActiveX Data Object (ADO) model can write arbitrary files can be exploited to compromise a user's system. This has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2.

Solution:
Disable Active Scripting or use another product.

Provided and/or discovered by:
1) Discovered independently by:
* http-equiv
* Andreas Sandblad of Secunia Research (reported to Microsoft on 2004-10-13).

2) http-equiv

Other References:
SA12321:
http://secunia.com/advisories/12321/

How to Disable Active Content in Internet Explorer:
http://support.microsoft.com/default.as ... us;q154036

source
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”