- http://www.techweb.com/article/printableAr…_section=700027
October 18, 2006
"Microsoft on Wednesday launched the first major update to Internet Explorer in five years… IE 7 for Windows XP and Windows Server 2003 can be downloaded from here*… The most controversial aspect of IE 7 has been Microsoft's decision to push the update to all users who have Automatic Updates enabled. Although users can reject IE 7 – and continue using their current edition of Internet Explorer – Microsoft will begin rolling out the browser as a "High priority" update next month… Microsoft has made one change late in the game. After IE 7 has installed, it will tell the user which search engine is the current default – grabbed from IE 5 or IE 6 – and then ask if they want to make a new choice. The process is similar to, but not identical, to the choice that Windows Vista users will face when they upgrade from Windows XP…"
* http://www.microsoft.com/windows/ie/default.mspx
- http://secunia.com/advisories/22477
Release Date: 2006-10-19
Critical: Less critical
Impact: Exposure of sensitive information
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 7.x …
…The vulnerability is caused due to an error in the handling of redirections for URLs with the "mhtml:" URI handler. This can be exploited to access documents served from another web site.
Secunia has constructed a test, which is available at: http://secunia.com/Internet_Explorer_Arbit…erability_Test/
Secunia has confirmed the vulnerability on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2. Other versions may also be affected.
Solution: Disable active scripting support…"
Information on Reports of IE 7 Vulnerability
- http://blogs.technet.com/msrc/archive/2006…nerability.aspx
October 19, 2006
"…The issue concerned in these reports is not in Internet Explorer 7 (or any other version) at all. Rather, it is in a different Windows component, specifically a component in Outlook Express. While these reports use Internet Explorer as a vector the vulnerability itself is in Outlook Express. While we are aware that the issue has been publicly disclosed, we’re not aware of it being used in any attacks against customers. We do have this under investigation and are monitoring the situation closely and we’ll take appropriate action to protect our customers once we’ve completed the investigation…"
- http://isc.sans.org/diary.php?storyid=1797
Last Updated: 2006-10-20 02:05:22 UTC
"…After analyzing this security vulnerability, we have to disappoint you – it's nothing new. Actually, this vulnerability was announced way back in April this year for Internet Explorer 6 ( http://secunia.com/advisories/19738 ). It is still not patched, so besides IE7, this vulnerability can be exploited in a fully patched IE6 installation as well.
So what's going on here, did Microsoft just use old code? Not really. The vulnerability exists in the MSXML ActiveX component which is actually part of Outlook Express (so it -is- installed on every machine as well). The exploit uses a "double" redirection trick – it will first create an Msxml2.XMLHTTP ActiveX object which is then used to retrieve a web page from the same server that the original web page is hosted on (one containing the exploit). This web page is actually just a redirection (302) which uses a mhtml: URI. This causes the ActiveX object to retrieve any other web page referenced by the mhtml: URI, which can be referenced from the original web page.
In other words, this exploit can be used by an attacker to possibly retrieve other data that your browser has access to. While stealing information like banking data is possible, our testing showed that only content of the web page can be retrieved by the attacker – they can not steal your credentials and they can not retrieve that data unless you are logged in to your bank account at the same time when you visit the web page hosting the exploit.
It looks like Microsoft once again got caught into "ancient" bugs which were already present on the machine (we do wonder why this hasn't been fixed before though). One thing worth noting is that Internet Explorer 7 has a native XMLHTTPRequest object implementation so theoretically it should be possible to disable the ActiveX object, but pages using it would have to be rewritten (hence support for the ActiveX object). Further testing will show if the native support implementation is also vulnerable – we'll post new information as we get it."