CERT-In Vulnerability Note
CIVN-2004-0074
Microsoft Internet Explorer HTML Help control bypasses Local Machine Zone Lockdown
Original Issue Date:December 29, 2004
Severity Rating: MEDIUM
Systems Affected
Microsoft Internet Explorer 6
Overview
A vulnerability exists in Internet Explorer HTML Help ActiveX control resulting in possible execution of the arbitrary code.
Impact
A remote attacker can execute arbitrary code in the Local Computer zone.
Description
This vulnerability in Microsoft Internet Explorer is caused because HTML Help ActiveX control is not restricted by the Local Machine Zone Lockdown feature. The Lockdown feature in XP SP2 provides enhanced Local Zone security restrictions to mitigate the attack vector.
To exploit this vulnerability an attacker could host a webpage containing malicious scripts, which could be executed with the help of HTML ActiveX control object hhctrl.ocx on Local Computer Zone Exploit code for this vulnerability is available on the Internet. A Trojan called Fhel.A attempting to exploit this vulnerability has been reported by Symantec.
Workaround
Apply following workarounds in IE - Disable Active scripting and ActiveX controls
- Disable Drag and drop or copy and paste files
Solution
No patches are available from the vendor to address this vulnerability till date.
References
US CERT Vulnerability Note VU#939688
http://www.kb.cert.org/vuls/id/939688
Security Focus
http://www.securityfocus.com/archive/1/378885
http://www.securityfocus.com/bid/11467
Securitytracker advisory
http://www.securitytracker.com/alerts/2004/Oct/1011851.html
Symantec
http://securityresponse.symantec.com/avcenter/venc/data/trojan.phel.a.html
Xforce
http://xforce.iss.net/xforce/xfdb/17824
CVE Name
CAN-2004-0985
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|