CERT-In Vulnerability Note
CIVN-2004-0065
Vulnerabilities in Microsoft Internet Explorer bypassing download security warnings in XP SP2
Original Issue Date:November 24, 2004
Severity Rating: MEDIUM
Systems Affected
Microsoft Internet Explorer 6
Overview
Two vulnerabilities exist in Internet Explorer due to the processing of URL method containing irrelevant characters. These can be exploited by a remote attacker to download a malicious file as a "HTML document".
Impact
A remote attacker can create malicious file on the target system bypassing the XP SP2 executable download warning messages.
Description
Two vulnerabilities have been reported in Internet Explorer, which can be exploited by a malicious user to bypass security features in Microsoft Windows XP SP2 and download malicious files on the vulnerable system. Microsoft Windows XP SP2 has a security feature, which warns users when opening downloaded files of certain types.
1. An attacker can send a specially crafted HTTP header or refer a specially crafted URL to download a malicious file distinguished as a HTML file which gets downloaded without security warning in certain situations. 2. The execCommand method uses SaveAs Command to save the current Web page to a local file. An error when saving some documents using this function can be exploited to spoof the file extension in the "Save HTML Document" dialog. A remote user can invoke this function via a custom HTTP 404 Page Not Found error message to download arbitrary files to the target users system without the XP SP2 warning messages. Successful exploitation of these vulnerabilities requires Hide extension for known file types option enabled.
Workaround
Disable Active Scripting and the "Hide file extensions for known file types" option.
Vendor Information
Microsoft Corporation
http://www.microsoft.com/
References
Securitytracker advisory
http://securitytracker.com/alerts/2004/Nov/1012288.html
Secunia advisory
http://secunia.com/advisories/13203/
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|