Alert:Microsoft Security Bulletin - MS02-009

From: Russ (Russ.Cooper@RC.ON.CA)
Date: 03/15/02


Date:         Fri, 15 Mar 2002 03:53:04 -0500
From: Russ <Russ.Cooper@RC.ON.CA>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

http://www.microsoft.com/technet/security/bulletin/MS02-009.asp

Incorrect VBScript Handling in IE can Allow Web Pages to Read Local Files

Originally posted: February 21, 2002

Summary

Who should read this bulletin: Customers using Microsoft® Internet Explorer.

Impact of vulnerability: Information Disclosure

Maximum Severity Rating: Critical

Recommendation: Customers using IE should apply the patch.

Affected Software:
- Microsoft Internet Explorer 5.01
- Microsoft Internet Explorer 5.5
- Microsoft Internet Explorer 6.0

Technical description:

Frames are used in Internet Explorer to provide for a fuller browsing experience. By design, scripts in the frame of one site or domain should be prohibited from accessing the content of frames in another site or domain. However, a flaw exists in how VBScript is handled in IE relating to validating cross-domain access. This flaw can allow scripts of one domain to access the contents of another domain in a frame.

A malicious user could exploit this vulnerability by using scripting to extract the contents of frames in other domains, then sending that content back to their web site. This would enable the attacker to view files on the user's local machine or capture the contents of third-party web sites the user visited after leaving the attacker's site. The latter scenario could, in the worst case, enable the attacker to learn personal information like user names, passwords, or credit card information.

In both cases, the user would either have to go to a site under the attacker's control or view an HTML email sent by the attacker. In addition, the attacker would have to know the exact name and location of any files on the user's system. Further, the attacker could only gain access to files that can be displayed in a browser window, such as text files, HTML files, or image files.

Mitigating factors:
- The vulnerability could only be used to view files. It could not be used to create, delete, modify or execute them.
- The vulnerability would only allow an attacker to read files that can be opened in a browser window, such as image files, HTML files and text files. Other file types, such as binary files, executable files, Word documents, and so forth, could not be read.
- The attacker would need to specify the exact name and location of the file in order to read it.
- The email-borne attack scenario would be blocked if the user were using any of the following: Outlook 98 or 2000 with the Outlook Email Security Update installed; Outlook 2002; or Outlook Express 6.

Vulnerability identifier: CAN-2002-0052

This email is sent to NTBugtraq automatically as a service to my subscribers. Since its programmatically created, and since its been a long time since anyone paid actual money for my programming skills, it may or may not look that good...;-]

I can only hope that the information it does contain can be read well enough to serve its purpose.

Cheers,
Russ - Surgeon General of TruSecure Corporation/NTBugtraq Editor



Relevant Pages

  • Re: Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflo
    ... it is reported that Microsoft Internet Explorer 6 Service ... Pack 2 is not prone to this vulnerability. ... If applicable, customers are advised ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • SecurityFocus Microsoft Newsletter #163
    ... MICROSOFT VULNERABILITY SUMMARY ... Bugzilla Javascript Buglists Remote Information Disclosure V... ... Microsoft Internet Explorer DHTML Drag and Drop Local File S... ... Microsoft Windows Workstation Service Remote Buffer Overflow... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #165
    ... Tenable Security ... distribute, manage, and communicate vulnerability and intrusion detection ... Microsoft Internet Explorer MHTML Forced File Execution Vuln... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #301
    ... AGEphone SIP Packet Handling Buffer Overflow Vulnerability ... Microsoft Internet Explorer NMSA.ASFSourceMediaDescription Stack Overflow Vulnerability ... Microsoft Windows is reportedly prone to a remote denial-of-service vulnerability. ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #303
    ... Microsoft Management Console Zone Bypass Vulnerability ... Microsoft Windows Server Service Remote Buffer Overflow Vulnerability ... Microsoft Hyperlink Object Library Function Remote Buffer Overflow Vulnerability ... Microsoft Internet Explorer Source Element Cross-Domain Information Disclosure Vulnerability ...
    (Focus-Microsoft)