This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

IEv6 SP2 vuln - remote exploit

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.us-cert.gov/cas/bulletins/SB05-166.html#MSIE
"A vulnerability has been reported that could let a malicious remote user hide scripting code. The IE browser does not properly process certain javascript scripting code.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

- http://www.securitytracker.com/alerts/2005/Jun/1014174.html
June 12 2005
"…IE browser does not properly process certain javascript scripting code. A remote user can create specially crafted HTML that, when loaded by the target user will execute scripting code but will not display the scripting code via the View Source function. Instead of displaying the original HTML scripting code, IE will display the scripting results in the View Source window…"

:ph34r:
FYI…

Potential Internet Explorer COM Vulnerability
- http://isc.sans.org/diary.php?date=2005-06-29
Updated June 29th 2005 22:54 UTC
"SEC Consult reported a condition in Internet Explorer that may lead to an exploitable vulnerability. The advisory points out that Internet Explorer does not properly handle the instantiation of non-ActiveX COM objects from web pages. According to the write-up, "loading HTML documents with certain embedded CLSIDs results in null-pointer exceptions or memory corruption. in one case, we could leverage this bug to overwrite a function pointer in the data segment. it *may* be possible to exploit this issue to execute arbitrary code in the context of IE." The published proof-of-concept code demonstrates the issue by invoking the javaprxy.dll COM object and crashing Internet Explorer, as tested in Internet Explorer 6 on Windows XP Service Pack 2. Although there are no patches to address the issue, a work-around is to disable ActiveX support in the browser. For more information about this issue, see the SEC Consult advisory.
- http://www.sec-consult.com/184.html
"…Internet Explorer supports instantiation of non-ActiveX controls, e.g COM objects, via
FYI…

- http://isc.sans.org/diary.php?date=2005-07-02
Updated July 2nd 2005 19:13 UTC
"On Thursday, Microsoft released a security advisory describing a new unpatched vulnerability in javaprxy.dll. FrSIRT also released a bulletin yesterday. Microsoft updated their bulletin last night with some additional workarounds including requiring prompting for all ActiveX controls and/or disabling the javaprxy entirely. For those of you who must continue to use IE as a browser, we highly recommend that you look at these workarounds. This morning our friends at FrSIRT released a proof-of-concept that results in a shell open on a high TCP port, so we expect active exploitation attempts in the very near future…"

- http://www.microsoft.com/technet/security/…ory/903144.mspx
Updated: July 1, 2005: Advisory updated with additional mitigations and workarounds

- http://www.frsirt.com/english/advisories/2005/0935

:ph34r:
FYI…

- http://secunia.com/advisories/15891/
Changelog:
2005-07-05: Added CAN-reference and link to US-CERT vulnerability note.
Upgraded criticality to "Extremely critical". Updated "Description" and "Solution" section…
Solution:
The vendor recommends setting Internet and Local intranet security zone settings to "High", or unregister, disable or restrict access to the javaprxy.dll COM object (see Microsoft original advisory* for details). This may affect functionality…"

- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2087
"Description:
Internet Explorer 6.0.2900.2180 on Windows XP allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using javaprxy.dll. NOTE: it has been reported that the vendor could not reproduce this problem…"

- http://www.kb.cert.org/vuls/id/939605

* http://www.microsoft.com/technet/security/…ory/903144.mspx
• July 5, 2005: Advisory updated with Microsoft Download Center information for the registry key update that disables Javaprxy.dll in Internet Explorer

:ph34r:
Fix:

Vulnerability in JView Profiler Could Allow Remote Code Execution (903235) MS05-037
- http://www.microsoft.com/technet/security/…n/MS05-037.mspx
Issued: July 12, 2005
Version Number: 1.0
"…This update resolves a newly-discovered, public vulnerability. A COM object, the JView Profiler (Javaprxy.dll), when instantiated in Internet Explorer, contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system. Since the JView Profiler COM object was not designed to be accessed through Internet Explorer, this update sets the kill bit for the JView Profiler (Javaprxy.dll) COM object. The vulnerability is documented in the “Vulnerability Details” section of this bulletin.
If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights…"
Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical…"

:ph34r:
New, more…

- http://news.com.com/Unpatched+IE+flaws+rep…_3-5798893.html
July 21, 2005
"…Four proof-of-concept images that aim to exploit these flaws have been posted on the Web by Zalewski. Each of these has the potential to crash IE 6, the latest version of Microsoft's browser, even if it has been patched with Service Pack 2. Previous versions of IE may also be affected, according to a SecurityFocus posting. Two of the exploit images also cause memory and CPU problems…"
Internet Explorer JPEG Image Rendering Unspecified Buffer Overflow Vulnerability
- http://www.securityfocus.com/bid/14282
Vulnerable: Microsoft Internet Explorer 6.0 SP2
Internet Explorer JPEG Image Rendering CMP Fencepost Denial Of Service Vulnerability
- http://www.securityfocus.com/bid/14284
Vulnerable: Microsoft Internet Explorer 6.0 SP2
- http://archives.neohapsis.com/archives/ful…05-07/0289.html
"…MSIE and its proprietary JPEG decoder (apparently not shared with other Windows components?) …performed embarassingly poor…"

:ph34r: