Security Bulletin MS04-040 KB889293 An attacker could exploit the vulnerability by constructing a malicious Web Page that could potentially allow remote code execution if a user visited a malicious Web site. An attacker who successfully exploited this vulnerability could take complete control of an affected system. What is the scope of the vulnerability? This is a remote code execution vulnerability. If a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts that have full privileges. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges. What causes the vulnerability? An unchecked buffer in Internet Explorer processing of certain HTML elements such as FRAME and IFRAME elements. What are IFRAME elements? Inline Floating Frames (IFRAME) is a technology that allows Web authors to have increased control of the design and interaction of their Web pages. For more information about IFRAME elements, visit this Microsoft Developer Network (MSDN) Web site. How could an attacker exploit the vulnerability? An attacker could exploit this vulnerability by creating a malicious Web page and persuading the user to visit the page. When the user has visited the page, the attacker could access information from other Web sites, access local files on the system, or cause malicious code to run as the locally logged on user. What systems are primarily at risk from the vulnerability? This vulnerability requires a user to view Web sites for malicious action to occur. Therefore, any systems where Internet Explorer is used frequently, such as users’ workstations or terminal servers, are at the most risk from this vulnerability. Systems that are not typically used to visit Web sites, such as most server systems, are at a reduced risk. It should be noted that FRAME and IFRAME elements are not rendered in the restricted zone, which is the zone where Outlook Express and Outlook by default open HTML email messages. Exploitation of this vulnerability through e-mail therefore requires user interaction in the form of a malicious link in the e-mail message. See the Workarounds Section in this bulletin for more information about this. Are Windows 98, Windows 98 Second Edition or Windows Millennium Edition critically affected by this vulnerability? Yes. Windows 98, Windows 98 Second Edition, and Windows Millennium Edition are critically affected by this vulnerability. A Critical security update for these platforms is available and is provided as part of this security bulletin and can be downloaded from the Windows Update Web site. For more information about severity ratings, visit this Microsoft Web site. What does the update do? The update removes the vulnerability by modifying the way that Internet Explorer validates the length of a message while processing HTML elements. When this security bulletin was issued, had this vulnerability been publicly disclosed? Yes. This vulnerability has been publicly disclosed. It has been assigned Common Vulnerability and Exposure number CAN-2004-1050. When this security bulletin was issued, had Microsoft received any reports that this vulnerability was being exploited? Yes. When the security bulletin was released, Microsoft had received information that this vulnerability was being exploited.