| | |
Internet Explorer Bug lets you run DOS commands remotely
![]() |
Article from: securitytracker.com
To view working sample, go to:
http://sec.drorshalev.com/dev/luck/default.asp
Microsoft Internet Explorer showHelp() Domain Security Flaw Lets Remote Users Execute Commands
SecurityTracker Alert ID: 1006046
CVE Reference: CAN-2003-1328 (Links to External Site)
Date: Feb 5 2003
Impact: Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, User access via network
Fix Available: Yes Vendor Confirmed: Yes
Version(s): 5.01, 5.5, 6.0
Description: A vulnerability was reported in Microsoft Internet Explorer in the showHelp() function. A remote user can create HTML scripting code that could load and execute code on a target user's system.
Microsoft issued security bulletin MS03-004 warning that a remote user could execute commands on a target user's system. The bulletin describes a cumulative patch that also corrects two newly discovered cross-domain vulnerabilities.
In the first vulnerability, it is reported that a remote user can create HTML scripting code that can access information from another domain when certain dialog boxes are invoked. The affected dialog boxes were not disclosed. According to the report, IE 5.01 is not affected by this particular flaw.
[Editor's note: It appears that this first flaw may be related to our Alert ID #1005747 from December 2002 based on a report from Liu Die Yu regarding a flaw in showModalDialog(). However, Microsoft did not provide enough information in their advisory to confirm this. We will attempt to confirm this.]
Also, a vulnerability exists in the showHelp() function. A remote user could create HTML scripting code that opens a showHelp window to a specified local file and then send a specially crafted URL to a second showHelp window to gain access to information from a different security domain..
In both of these vulnerabilities, a remote user may also be able to execute existing binaries on the target user's system or load malicious code onto the target user's system.
Microsoft credits Andreas Sandblad for reporting the showHelp() cross-domain vulnerability.
Impact: A remote user could obtain information from a different security domain on the target user's system. A remote user could also load and execute arbitrary code on the target user's system.
Solution: The vendor has released the following patch:
http://www.microsoft.com/windows/ie/...47/default.asp
The IE 5.01 patch can be installed on Windows 2000 SP3 Systems running IE 5.01 SP3. The IE 5.5 patch can be installed on IE 5.5 SP2. The IE 6.0 patch can be installed on systems running IE 6.0 Gold. The IE 6.0 SP1 patch can be installed on IE 6.0 SP1.
Microsoft plans to include this fix in Internet Explorer 6.0 SP2.
This patch supersedes the patch described in MS02-068 and MS02-066.
Several caveats are described in the bulletin. According to the vendor, this patch will cause the window.showHelp() function to stop functioning. A separate patch (the latest HTML Help update available via Windows Update; 811630) will re-enable the window.showHelp() function with some restrictions. See the vendor's bulletin for more information.
Microsoft plans to issue Knowledge Base article 810847 regarding this issue, to be available shortly on the Microsoft Online Support web site:
http://support.microsoft.com/?scid=fh;en-us;kbhowto
To view working sample, go to:
http://sec.drorshalev.com/dev/luck/default.asp
Microsoft Internet Explorer showHelp() Domain Security Flaw Lets Remote Users Execute Commands
SecurityTracker Alert ID: 1006046
CVE Reference: CAN-2003-1328 (Links to External Site)
Date: Feb 5 2003
Impact: Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, User access via network
Fix Available: Yes Vendor Confirmed: Yes
Version(s): 5.01, 5.5, 6.0
Description: A vulnerability was reported in Microsoft Internet Explorer in the showHelp() function. A remote user can create HTML scripting code that could load and execute code on a target user's system.
Microsoft issued security bulletin MS03-004 warning that a remote user could execute commands on a target user's system. The bulletin describes a cumulative patch that also corrects two newly discovered cross-domain vulnerabilities.
In the first vulnerability, it is reported that a remote user can create HTML scripting code that can access information from another domain when certain dialog boxes are invoked. The affected dialog boxes were not disclosed. According to the report, IE 5.01 is not affected by this particular flaw.
[Editor's note: It appears that this first flaw may be related to our Alert ID #1005747 from December 2002 based on a report from Liu Die Yu regarding a flaw in showModalDialog(). However, Microsoft did not provide enough information in their advisory to confirm this. We will attempt to confirm this.]
Also, a vulnerability exists in the showHelp() function. A remote user could create HTML scripting code that opens a showHelp window to a specified local file and then send a specially crafted URL to a second showHelp window to gain access to information from a different security domain..
In both of these vulnerabilities, a remote user may also be able to execute existing binaries on the target user's system or load malicious code onto the target user's system.
Microsoft credits Andreas Sandblad for reporting the showHelp() cross-domain vulnerability.
Impact: A remote user could obtain information from a different security domain on the target user's system. A remote user could also load and execute arbitrary code on the target user's system.
Solution: The vendor has released the following patch:
http://www.microsoft.com/windows/ie/...47/default.asp
The IE 5.01 patch can be installed on Windows 2000 SP3 Systems running IE 5.01 SP3. The IE 5.5 patch can be installed on IE 5.5 SP2. The IE 6.0 patch can be installed on systems running IE 6.0 Gold. The IE 6.0 SP1 patch can be installed on IE 6.0 SP1.
Microsoft plans to include this fix in Internet Explorer 6.0 SP2.
This patch supersedes the patch described in MS02-068 and MS02-066.
Several caveats are described in the bulletin. According to the vendor, this patch will cause the window.showHelp() function to stop functioning. A separate patch (the latest HTML Help update available via Windows Update; 811630) will re-enable the window.showHelp() function with some restrictions. See the vendor's bulletin for more information.
Microsoft plans to issue Knowledge Base article 810847 regarding this issue, to be available shortly on the Microsoft Online Support web site:
http://support.microsoft.com/?scid=fh;en-us;kbhowto
0
#2 Feb 11th, 2003
/me is in linux
-Ryan Hoffman
.NET Specialist / Webmaster, Extended64.com.
Please do not email or PM me with support questions. Please direct them to the forums instead.
.NET Specialist / Webmaster, Extended64.com.
Please do not email or PM me with support questions. Please direct them to the forums instead.
•
•
Join Date: Aug 2003
Posts: 10
Reputation:
Solved Threads: 0
go to MS and download their patch:
http://www.microsoft.com/downloads/d...displaylang=en
that exploit won't work again.
http://www.microsoft.com/downloads/d...displaylang=en
that exploit won't work again.
![]() |
Similar Threads
- News Story: Internet Explorer fault (Network Security)
- News Story: Microsoft announces host of new Internet Explorer 8 security features (Web Browsers)
- News Story: New Internet Explorer 8 functionality revealed (Web Browsers)
- Internet explorer only loads error page http:/// (Web Browsers)
- internet explorer script error (Windows 95 / 98 / Me)
- Internet Explorer Corruption! Error in SHELLEXT.DLL (Web Browsers)
- internet explorer error messages (Web Browsers)
Other Threads in the Web Browsers Forum
- Previous Thread: IE Problems
- Next Thread: internet explorer problem (aaaaaaarrrrrrgggggh)
| Thread Tools | Search this Thread |
aiim2009 andrewlippmann aol apple awesomebar britain browser browserproblems browsers browsing budget bug bughunt censorship childabuse chrome client code compuserve contest crash development dns email error eu europe explorer facebook fennec fileeditmissing firefox flash gecko google government history ie7 ie8 internet internet.broadband internetexplorer internetexplorer8 internetusage iphone linux malware marshallmcluhan media memory microsoft mitmedialab mobilebrowsers mosaic mozilla music netscape networking news newyork olympics onlinecommunities opensource opera opera.software patch plugins porn privacy problem safari save seamonkey security server sex social software survey surveys teenagers television testing thunderbird twitter u.s. uk update usenet users utest video web webbrowser webdevelopment webusage windowslivemail worldrecord worldwideweb xp






