Microsoft Internet Explorer CHTSKDIC.DLL Arbitrary Code Execution Vulnerability
BID:19529
CVE-2006-4193 |Info
Microsoft Internet Explorer CHTSKDIC.DLL Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 19529 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-4193 CVE-2007-0942 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2006 12:00AM |
| Updated: | May 17 2007 09:38PM |
| Credit: | nop has been credited with the discovery of this vulnerability. |
| Vulnerable: |
Nortel Networks Contact Center Web Client Nortel Networks Contact Center Multimedia Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Manager Nortel Networks Contact Center Express Nortel Networks Contact Center Administration 0 Nortel Networks Contact Center - Symposium Agent 0 Nortel Networks Contact Center Nortel Networks Centrex IP Client Manager Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 7.0.5730 .11 Microsoft Internet Explorer 5.0.1 SP4 Microsoft Internet Explorer 5.0.1 SP3 Microsoft Internet Explorer 5.0.1 SP2 Microsoft Internet Explorer 5.0.1 SP1 Microsoft Internet Explorer 5.0.1 for Windows NT 4.0 Microsoft Internet Explorer 5.0.1 for Windows 98 Microsoft Internet Explorer 5.0.1 for Windows 95 Microsoft Internet Explorer 5.0.1 for Windows 2000 Microsoft Internet Explorer 5.0.1 Microsoft Internet Explorer 7.0 beta3 Microsoft Internet Explorer 7.0 beta2 Microsoft Internet Explorer 7.0 beta1 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 SP2 - do not use Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 Microsoft Internet Explorer 5.0.1 SP4 HP Storage Management Appliance 2.1 Avaya Web Messenger 0 Avaya VPNmanagerTM Console 0 Avaya Visual Vector Client 0 Avaya Visual Messenger TM 0 Avaya Unified Messenger (r) 0 Avaya Unified Communications Center S3400 Avaya Unified Communication Center Avaya Speech Access 0 Avaya Outbound Contact Management 0 Avaya Operational Analyst 0 Avaya OctelDesignerTM 0 Avaya OctelAccess(r) Server 0 Avaya Network Reporting 0 Avaya Modular Messaging (MSS) 2.0 SP4 Avaya Modular Messaging (MSS) 2.0 Avaya Modular Messaging (MSS) 1.1 Avaya Modular Messaging (MAS) 3.0 Avaya Modular Messaging (MAS) Avaya Modular Messaging S3400 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server 0 Avaya IP Softphone 0 Avaya IP Agent 0 Avaya Interaction Center - Voice Quick Start 0 Avaya Interaction Center 0 Avaya Integrated Management 2.1 Avaya Integrated Management Avaya Enterprise Management 0 Avaya CVLAN Avaya Customer Interaction Express (CIE) User Interface 1.0 Avaya Customer Interaction Express (CIE) Server 1.0 Avaya Contact Center Express 0 Avaya Computer Telephony 0 Avaya CMS Supervisor 0 Avaya CIE 1.0 Avaya Basic Call Management System Reporting Desktop server Avaya Basic Call Management System Reporting Desktop 0 Avaya Agent Access 0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CHTSKDIC.DLL Arbitrary Code Execution Vulnerability
Microsoft Internet Explorer is prone to an arbitrary code-execution vulnerability because the application fails to load a DLL library when instantiated as an ActiveX control.
An attacker may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users and may cause arbitrary code to run within the context of the user running the application.
Microsoft Internet Explorer is prone to an arbitrary code-execution vulnerability because the application fails to load a DLL library when instantiated as an ActiveX control.
An attacker may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users and may cause arbitrary code to run within the context of the user running the application.
Exploit / POC
Microsoft Internet Explorer CHTSKDIC.DLL Arbitrary Code Execution Vulnerability
This issue can be exploited via a web client.
The following proof of concept is available:
This issue can be exploited via a web client.
The following proof of concept is available:
Solution / Fix
Microsoft Internet Explorer CHTSKDIC.DLL Arbitrary Code Execution Vulnerability
Solution:
Microsoft has released security advisory MS07-027 to address this issue in supported versions of affected applications.
Microsoft Internet Explorer 7.0 beta1
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0 SP2 - do not use
Microsoft Internet Explorer 5.0.1 SP4
Solution:
Microsoft has released security advisory MS07-027 to address this issue in supported versions of affected applications.
Microsoft Internet Explorer 7.0 beta1
-
Microsoft Cumulative Update for Internet Explorer 7 for Windows Server 2003 (KB931768)
Windows Internet Explorer 7 for Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=0F173D60-6FD0 -4C92-BB2A-A7A78707E35F&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 for Windows Server 2003 64-bit Itanium Edition (KB931768)
Windows Internet Explorer 7 for Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?familyid=1944BCFA-B0BC -4BD5-9089-A618EA43EA49&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB931768)
ows Internet Explorer 7 for Windows Server 2003 x64 Edition Service Pack 1 and Windows Server 2003 x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=404A48A2-5765 -4AFA-94BF-E97212AA14EF&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 for Windows XP Service Pack 2 (KB931768)
Windows Internet Explorer 7 for Windows XP Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=7A778D93-9D85 -4217-8CC0-5C494D954CA0&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 for Windows XP x64 Edition (KB931768)
Windows Internet Explorer 7 for Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=29938ED4-F8BB -4793-897C-966BA7F4830C&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 in Windows Vista (KB931768)
Windows Internet Explorer 7 in Windows Vista
http://www.microsoft.com/downloads/details.aspx?familyid=0C65FAD3-BAAE -46C4-B453-84CF28B15F50&displaylang=en -
Microsoft Cumulative Update for Internet Explorer 7 in Windows Vista x64 Edition (KB931768)
Windows Internet Explorer 7 in Windows Vista x64 Edition
http://www.microsoft.com/downloads/details.aspx?familyid=74AFEA3D-79DF -4B64-BF30-B8E5C55CAB2B&displaylang=en
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Update for Internet Explorer 6 SP1 (KB931768)
Microsoft Internet Explorer 6 Service Pack 1 when installed on Windows 2000 Service Pack 4
http://www.microsoft.com/downloads/details.aspx?familyid=03FC8E0C-DEC5 -48D1-9A34-3B639F185F7D&displaylang=en
Microsoft Internet Explorer 6.0 SP2 - do not use
-
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 (KB931768)
Microsoft Internet Explorer 6 for Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=D249089D-BB8E -4B86-AB8E-18C52844ACB2&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB931768)
Microsoft Internet Explorer 6 for Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?familyid=D52C0AFD-CC3A -4A5C-B91B-E006D497BC26&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 x64 Edition (KB931768)
Microsoft Internet Explorer 6 for Windows Server 2003 x64 Edition Service Pack 1 and Windows Server 2003 x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=94B83BDD-2BD1 -43E4-BABF-68135D253293&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows XP Service Pack 2 (KB931768)
Microsoft Internet Explorer 6 for Windows XP Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=EFC6BE04-0D6B -4639-8485-DA1525F6BC52&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows XP x64 Edition (KB931768)
Microsoft Internet Explorer 6 for Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=A077BE20-C379 -4386-B478-80197A4A4ABC&displaylang=en
Microsoft Internet Explorer 5.0.1 SP4
-
Microsoft Cumulative Update for Internet Explorer 5.01 Service Pack 4 (KB931768)
http://www.microsoft.com/downloads/details.aspx?familyid=67AE3381-16B2 -4B34-B95C-69EE7D58B357&displaylang=en
References
Microsoft Internet Explorer CHTSKDIC.DLL Arbitrary Code Execution Vulnerability
References:
References: