Microsoft Internet Explorer XML Handling Remote Code Execution Vulnerability
BID:32721
Info
Microsoft Internet Explorer XML Handling Remote Code Execution Vulnerability
| Bugtraq ID: | 32721 |
| Class: | Design Error |
| CVE: |
CVE-2008-4844 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2008 12:00AM |
| Updated: | Feb 12 2010 10:11AM |
| Credit: | GreySign |
| Vulnerable: |
Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service MPS 100 0 Nortel Networks Contact Center NCC 0 Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Manager Nortel Networks Contact Center Express Nortel Networks Contact Center Nortel Networks CallPilot 703t Nortel Networks CallPilot 600r Nortel Networks CallPilot 201i Nortel Networks CallPilot 1005r Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 5.0.1 SP4 Microsoft Internet Explorer 5.0.1 SP3 Microsoft Internet Explorer 5.0.1 SP2 Microsoft Internet Explorer 5.0.1 SP1 Microsoft Internet Explorer 5.0.1 Microsoft Internet Explorer 8 beta 2 Microsoft Internet Explorer 8 Beta 1 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 HP Storage Management Appliance III HP Storage Management Appliance II HP Storage Management Appliance I HP Storage Management Appliance 2.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer XML Handling Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
NOTE: Symantec has received reports that this issue is being actively exploited in the wild.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
NOTE: Symantec has received reports that this issue is being actively exploited in the wild.
Exploit / POC
Microsoft Internet Explorer XML Handling Remote Code Execution Vulnerability
Symantec has received reports that this issue is being actively exploited in the wild.
Exploits are publicly available. Note that these exploits have been observed to crash vulnerable versions of Internet Explorer, but Symantec has not completely verified them.
Use caution when handling these exploits. Test them only in isolated environments because they may be malicious.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following commercial exploit is available through Immunity CANVAS Early Updates:
https://www.immunityinc.com/downloads/immpartners/msparsing_xml.tar.gz
Symantec has received reports that this issue is being actively exploited in the wild.
Exploits are publicly available. Note that these exploits have been observed to crash vulnerable versions of Internet Explorer, but Symantec has not completely verified them.
Use caution when handling these exploits. Test them only in isolated environments because they may be malicious.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following commercial exploit is available through Immunity CANVAS Early Updates:
https://www.immunityinc.com/downloads/immpartners/msparsing_xml.tar.gz
Solution / Fix
Microsoft Internet Explorer XML Handling Remote Code Execution Vulnerability
Solution:
Vendor updates are available.
Microsoft Internet Explorer 7.0
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
Microsoft Internet Explorer 5.0.1 SP1
Microsoft Internet Explorer 5.0.1 SP4
Microsoft Internet Explorer 5.0.1 SP2
Microsoft Internet Explorer 5.0.1 SP3
Microsoft Internet Explorer 5.0.1
Solution:
Vendor updates are available.
Microsoft Internet Explorer 7.0
-
Microsoft Security Update for Internet Explorer 7 for Windows Server 2003 (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=388847ec-817e -45cf-8fa7-32c7e1f57f80 -
Microsoft Security Update for Internet Explorer 7 for Windows Server 2003 64-bit Itanium Edition (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=97d6c093-f68d -4ddf-8e3c-f29662a1940f -
Microsoft Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=2ae17caf-6204 -470e-8480-380d3d505657 -
Microsoft Security Update for Internet Explorer 7 for Windows XP (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=0190a289-164e -41a7-8c01-fa1aaed3f531 -
Microsoft Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=9ba71e23-8cef -4399-b215-983b0dcf5cb5 -
Microsoft Security Update for Internet Explorer 7 in Windows Server 2008 (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=5552e564-dd1c -4e2a-9a42-6317522c884d -
Microsoft Security Update for Internet Explorer 7 in Windows Server 2008 64-bit Itanium Edition (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=06cb502a-6818 -4599-aa24-6eddb83e4b84 -
Microsoft Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=889c6eb1-7d1f -4e60-b637-535cb6e4e443 -
Microsoft Security Update for Internet Explorer 7 in Windows Vista (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=7887111d-4fac -4823-bdd2-a18d9468fdf0 -
Microsoft Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=69979d92-8d45 -47fe-ac4c-c2f1f23cf1fb
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Security Update for Internet Explorer 6 SP1 (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=124c14b6-9323 -4f6f-902b-727aa56444bc
Microsoft Internet Explorer 6.0
-
Microsoft Security Update for Internet Explorer for Windows Server 2003 (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=d81e9cf9-ce0c -463a-a359-49a348cb89ae -
Microsoft Security Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=18016305-7f72 -47f6-ab4c-94282289bf5f -
Microsoft Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=015df302-d79f -43a1-b5c5-32ac04de0510 -
Microsoft Security Update for Internet Explorer for Windows XP (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=1d83e0af-46fa -4bfc-ba57-635435a7ef2d -
Microsoft Security Update for Internet Explorer for Windows XP x64 Edition (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=a585cb73-2c1a -4fa8-862a-ad6aeaeaf2f8
Microsoft Internet Explorer 5.0.1 SP1
-
Microsoft Security Update for Internet Explorer 5.01 Service Pack 4 (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=d3e18732-47f1 -40ce-999c-d1fd283bf138&displaylang=en
Microsoft Internet Explorer 5.0.1 SP4
-
Microsoft Security Update for Internet Explorer 5.01 Service Pack 4 (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=d3e18732-47f1 -40ce-999c-d1fd283bf138&displaylang=en
Microsoft Internet Explorer 5.0.1 SP2
-
Microsoft Security Update for Internet Explorer 5.01 Service Pack 4 (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=d3e18732-47f1 -40ce-999c-d1fd283bf138&displaylang=en
Microsoft Internet Explorer 5.0.1 SP3
-
Microsoft Security Update for Internet Explorer 5.01 Service Pack 4 (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=d3e18732-47f1 -40ce-999c-d1fd283bf138&displaylang=en
Microsoft Internet Explorer 5.0.1
-
Microsoft Security Update for Internet Explorer 5.01 Service Pack 4 (KB960714)
http://www.microsoft.com/downloads/details.aspx?familyid=d3e18732-47f1 -40ce-999c-d1fd283bf138&displaylang=en
References
Microsoft Internet Explorer XML Handling Remote Code Execution Vulnerability
References:
References:
- Clarification on the various workarounds from the recent IE advisory (Microsoft)
- Alert: IE70DAY attack code has been linked to the use of trojan horse (GreySign)
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition (CWE)
- Microsoft Internet Explorer Homepage (Microsoft)
- Microsoft Security Advisory 961051 Updated (Microsoft Security Response Center (MSRC))
- Microsoft Security Bulletin Advance Notification for December 2008 (Microsoft)
- MS08-078 and the SDL (Microsoft)
- New Web attack exploits unpatched IE flaw (Robert McMillan)
- ASA-2008-510 - MS08-078 Security Update for Internet Explorer (960714) (Avaya)
- EEYEZD-20081209 Microsoft Internet Explorer 7 XML Zero-Day (eEye Digital Security)
- HPSBST02397 SSRT080187 rev.1 - Storage Management Appliance (SMA), Microsoft Pat (HP)
- Microsoft Security Advisory 961051 (Microsoft)
- Microsoft Security Bulletin MS08-078 (Microsoft)
- Nortel Response to Microsoft Security Bulletin MS08-078 (Nortel Networks)
- VU#493881 - Microsoft Internet Explorer 7 XML parsing memory corruption (US-CERT)