PDA

View Full Version : Serious IE vulnerabilities


LeRoi
06-08-2004, 12:05 PM
TITLE:
Internet Explorer Local Resource Access and Cross-Zone Scripting
Vulnerabilities

SECUNIA ADVISORY ID:
SA11793

VERIFY ADVISORY:
http://secunia.com/advisories/11793/

CRITICAL:
Extremely critical

IMPACT:
Security Bypass, System access

WHERE:
From remote

SOFTWARE:
Microsoft Internet Explorer 6

DESCRIPTION:
Two vulnerabilities have been reported in Internet Explorer, which in
combination with other known issues can be exploited by malicious
people to compromise a user's system.

1) A variant of the "ms-its:" local resource access vulnerability can
be exploited via a specially crafted URL in the "Location:" HTTP
header to open locally installed "CHM" help files.

Example:
URL:ms-its:C:\WINDOWS\Help\iexplore.chm::/iegetsrt.htm

2) A cross-zone scripting error can be exploited to execute files in
the "Local Machine" security zone.

Secunia has confirmed the vulnerabilities in a fully patched system
with Internet Explorer 6.0. It has been reported that the preliminary
SP2 prevents exploitation by denying access.

Successful exploitation requires that a user can be tricked into
following a link or view a malicious HTML document.

NOTE: The vulnerabilities are actively being exploited in the wild to
install adware on users' systems.

SOLUTION:
Disable Active Scripting support for all but trusted web sites.

Remove support for the "ms-its:" URI handler.

PROVIDED AND/OR DISCOVERED BY:
Originally discovered in the wild.
Detailed analysis of exploit by Jelmer.

OTHER REFERENCES:
Jelmer's posting on Full-Disclosure:
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0104.html

carolj100
06-08-2004, 12:46 PM
Thanks, LeRoi. Sure am glad I don't have to use IE much.

D_Spider
06-09-2004, 02:05 AM
Thanks, LeRoi--
Does this affect those of us who use an IE-based browser?

ZEUS_GB
06-09-2004, 03:29 AM
IE is one big security vulnerability!

Thanks for the heads up LeRoi!

Neil
06-09-2004, 01:04 PM
Thanks for the info LeRoi. So glad you convinced me about using a diffrent browser and now i'm hooked on Mozilla http://www.mypcclinic.com/forums/images/smilies/67.gif

Neil

BlueIndian
06-09-2004, 03:15 PM
I use the browser MyIE2. Will thay affect the MyIE2?

gem
06-10-2004, 06:52 AM
:hi: I posted a while ago about my confusion after doing a windows security update and I started seeing multilple ixplorers when doing an alt,cntrl, delete, to see what was running off and on during the day. i remove them and as soon as i start browising and opening new windows,, i get more ixplorers which i then start deleteing.. Anyone know how to stop getting these buggers. I only use internete explorer as a browser now, use to use That and crazy but to conserve disk I deleted it ,, now if i used crazy i never saw the ixplore show up,,,will check back for input thanks in advance Gem :amie:

GolfProRM
06-10-2004, 09:19 AM
I use the browser MyIE2. Will thay affect the MyIE2?

Yes it will...