Does IE object type overflow work only on an Administrator account?

From: kathy tuckey (kdtuckey_at_hotmail.com)
Date: 07/24/03

  • Next message: deepcode .: "Shellcoding ... again."
    To: vuln-dev@securityfocus.com
    Date: Thu, 24 Jul 2003 18:03:07 +0000
    
    

    Does IE object type overflow work only on an Administrator account?

    I'm puzzled by the following behaviour on a default install of WindowsXP Pro
    (IE 6.0):

    Using html page containing: <object type =
    "[/x64]AAAAAAAAAAAAAAAAAA">whatever</object>

    As a user with Administrator priveleges with default security settings, IE
    crashes (buffer is overflowed). As a user with Administrator priveleges with
    IE security settings set to "high", IE still crashes.

    As a user with limited priveleges, the page loads fine and "whatever"
    appears on the screen. IE doesn't crash. The urlmon function causing the
    buffer overflow is never called by IE. (the breakpoint doesn't break) In
    this case, changing IE's security settings to "low" doesn't make a
    difference.

    Does IE treat a user with limited priveleges differently than with
    Administrator priveleges? Am I simply missing a setting somewhere?

    Any words of wisdom?

    Thanks,
    Kathy

    _________________________________________________________________
    Protect your PC - get McAfee.com VirusScan Online
    http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=3963


  • Next message: deepcode .: "Shellcoding ... again."

    Relevant Pages

    • Re: Server cannot access application directory D:xxx. The directory does not exist or is not accessi
      ... different logon session will see it. ... The directory does not exist or is not accessible because of security settings." ... Security settings for directory D:\xxx are the following: Administrator: Full Control ... I have looked up the members of the "Administrators" group: The only member is the "Administrator" User who already had all rights on the directory. ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: Apply security settings or take ownership: access denied.
      ... I would also double check that you are logged-in as administrator. ... When I try to reapply the security settings of higher-level ... How can I take the ownership of these ...
      (microsoft.public.windows.server.security)
    • ActiveX controls are prohibited
      ... My security settings in IE are the default, ... double checked that the Administrator account is part of the Administrators ... Group, which according to the description, still has complete control over ... in the error page) and did what it said, which is to delete the 2 ActiveX ...
      (microsoft.public.win2000.windows_update)
    • Re: Users and printing problems
      ... > 2) did you check the security settings of the printer? ... If I set a user as an administrator, ... Spike ...
      (microsoft.public.windowsxp.security_admin)
    • Admin cannot change Local Security Policies
      ... I have an XP Professional machine and almost all Security Settings have the ... options greyed out when logged in as administrator. ... There is even a little lock icon ... In "User Rights Assignments",, Administrators are said to have the rights to change all these settings. ...
      (microsoft.public.windowsxp.security_admin)

  • Quantcast