Microsoft Internet Explorer Drag and Drop Vulnerability
BID:11770
Info
Microsoft Internet Explorer Drag and Drop Vulnerability
| Bugtraq ID: | 11770 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2004 12:00AM |
| Updated: | Nov 28 2004 12:00AM |
| Credit: | Announced by Paul <[email protected]>. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP Embedded SP1 Microsoft Windows XP Embedded Microsoft Windows XP 64-bit Edition Version 2003 SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Internet Explorer 6.0 SP2 - do not use Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Drag and Drop Vulnerability
A security researcher has reported a simpler variant of the vulnerability described in BID 11466. In that vulnerability, it was theoretically possible for external and untrustworthy HTML / script code to be executed if a maliciously constructed file were "dragged and dropped" and then clicked on. This process involved the victim user manually clicking the file to open it. The author of this report has stated that the new variant removes the step of manually clicking the file. This may allow for automatic compromise if the user will "drag and drop" a malicious file.
A security researcher has reported a simpler variant of the vulnerability described in BID 11466. In that vulnerability, it was theoretically possible for external and untrustworthy HTML / script code to be executed if a maliciously constructed file were "dragged and dropped" and then clicked on. This process involved the victim user manually clicking the file to open it. The author of this report has stated that the new variant removes the step of manually clicking the file. This may allow for automatic compromise if the user will "drag and drop" a malicious file.
Exploit / POC
Microsoft Internet Explorer Drag and Drop Vulnerability
A proof of concept is available at:
http ://freehost07.websamba.com/greyhats/longnamevuln.htm
A proof of concept is available at:
http ://freehost07.websamba.com/greyhats/longnamevuln.htm
Solution / Fix
Microsoft Internet Explorer Drag and Drop Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer Drag and Drop Vulnerability
References:
References: