Showing posts with label Zero-day Bug. Show all posts
Showing posts with label Zero-day Bug. Show all posts

New Zero-Day Bug Crashes Internet Explorer

Because the vulnerability can be exploited by a single malicious HTML tag, IE could be brought to its knees if its user simply surfs to a nasty Web site.

Microsoft (NSDQ: MSFT)'s Internet Explorer browser crashes when attacked through a new unpatched vulnerability, security companies told TechWeb Friday.

The zero-day bug occurs within the "mshtml" library when a malformed HTML tag with an abnormally large number of script handlers is fed to the browser. According to the researcher who posted the initial description to the Bugtraq security mailing list, attackers can easily crash IE by flooding its buffer.

The researcher, Michal Zalewski, also released proof-of-concept code that crashes the latest IE release on a fully-patched edition of Windows XP SP2.

Symantec (NSDQ: SYMC) noted in an alert to customers of its DeepSight system that its staff had confirmed the proof-of-concept code crashed IE in some, but not all, situations. Also on Friday, rival McAfee released a new signature to anti-virus customers that detects the proof-of-concept exploit.

Because the vulnerability can be exploited by a single malicious HTML tag, IE could be brought to its knees if its user simply surfed to a nasty Web site. Symantec, however, warned that the bug may be even more serious. "Further investigation in the details of exploiting the vulnerability to determine the possibility of code execution are currently under way," the company's advisory read.

If that's the case, IE users may face a new major hijack risk.

There are no known work-arounds, and Microsoft did not immediately respond to questions about its plans for the vulnerability.

"Until more information is available it is advised that all users take extra caution in their browsing activities, and limit web access to trusted web sources only," Symantec recommended.

Zalewski, however, noted that other browsers, such as Firefox and Opera, were not susceptible to the attack, implicitly advising users to consider an alternate browser.

Finally, he pre-empted Microsoft, which always criticizes researchers who disclose bugs before the Redmond, Wash.-based developer can create a fix, with a blast of his own.

"I eagerly await due reprimend [sic] from Microsoft for not disclosing this vulnerability in a manner that benefits them most," Zalewski said in his Bugtraq posting.

[Source: informationweek]

Zero-day flaw haunts Internet Explorer

Zero-day flaw haunts Internet ExplorerAn unpatched cross-domain vulnerability in Microsoft’s flagship Internet Explorer browser could expose Windows users to cookie hijacks and credentials theft attacks, according to a warning from security researchers.

The zero-day flaw, which has been reported to Microsoft, is a variation of Eduardo Vela’s IE Ghost Busters talk:

Do you believe in ghosts? Imagine an invisible script that silently follows you while you surf, even after changing the URL 1,000 times and you are feeling completely safe. Now imagine that the ghost is able to see everything you do, including what you are surfing and what you are typing (passwords included), and even guess your next move.

No downloading required, no user confirmation, no ActiveX. In other words: no strings attached. We will examine the power of a resident script and the power of a global cross-domain. Also, we will go through the steps of how to find cross-domains and resident scripts.

Details of the new variation have been posted online by the Ph4nt0m Security Team (translation here).

It affects Internet Explorer 6 on Windows XP SP2 and SP3.  The new IE 7 browser is not affected because Microsoft changed the way Javascript protocol URLs are handled to prevent these types of attacks.

Security researcher Aviv Raff has created a test page that confirms the attack vector in IE 6. This screenshot shows a script loaded in one domain (raffon.net) showing a cookie of a different domain (google.com):

Zero-day flaw haunts Internet Explorer

In the absence of a patch, IE users are strongly encouraged to upgrade to IE 7.  Or, as always, consider using an alternative browser.

UPDATE: An alert from US-CERT spells out the risks:

This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary script in the context of another domain. This could allow an attacker to take a variety of actions, including stealing cookies, hijacking a web session, or stealing authentication credentials.

Secunia rates this a moderately critical issue.

In the absence of a patch, IE users are strongly encouraged to upgrade to IE 7.  Or, as always, consider using an alternative browser.

UPDATE: An alert from US-CERT spells out the risks:

This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary script in the context of another domain. This could allow an attacker to take a variety of actions, including stealing cookies, hijacking a web session, or stealing authentication credentials.

Secunia rates this a moderately critical issue.


[Source: zdnet]