Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
BID:37085
Info
Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
| Bugtraq ID: | 37085 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3672 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2009 12:00AM |
| Updated: | Dec 14 2009 10:43PM |
| Credit: | [email protected] |
| Vulnerable: |
Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Peri Workstation 0 Nortel Networks Peri Application 0 Nortel Networks Multimedia Comm Mas 0 Nortel Networks Media Processing Svr 500 Rel 3.0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Nortel Networks Media Processing Svr 100 0 Nortel Networks Media Processing Server Nortel Networks Contact Center Multimedia & Outbound 7.0 Nortel Networks Contact Center Multimedia & Outbound 6.0 Nortel Networks Contact Center Multimedia Nortel Networks Contact Center Express Nortel Networks Contact Center Administration CCMA 7.0 Nortel Networks Contact Center Administration CCMA 6.0 Nortel Networks Contact Center Administration 0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 600r Nortel Networks CallPilot 202i Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1005r Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the computer. Failed attacks may cause denial-of-service conditions.
Internet Explorer 6 and 7 on Windows XP and Vista are vulnerable; other versions may also be affected.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the computer. Failed attacks may cause denial-of-service conditions.
Internet Explorer 6 and 7 on Windows XP and Vista are vulnerable; other versions may also be affected.
Exploit / POC
Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
A poof of concept ('37085-2.html') and exploit ('37085.html') are available.
UPDATE: Symantec has verified that the available exploit is functional but not very reliable. However, the exploit code could be modified to be more reliable.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A Metasploit framework exploit module ('37085.rb') is available.
A poof of concept ('37085-2.html') and exploit ('37085.html') are available.
UPDATE: Symantec has verified that the available exploit is functional but not very reliable. However, the exploit code could be modified to be more reliable.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A Metasploit framework exploit module ('37085.rb') is available.
Solution / Fix
Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for details.
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 7.0
Microsoft Internet Explorer 6.0
Solution:
Updates are available. Please see the references for details.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Update for Internet Explorer 6 SP1 (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=7fb6261c-6895 -4f79-be2c-bb110874a19c
Microsoft Internet Explorer 7.0
-
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=7bdba030-e2c6 -44ac-bb5f-24ae8ec372a2 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 64-bit Itanium Edition (K
http://www.microsoft.com/downloads/details.aspx?FamilyID=72d44de7-dfc5 -4667-a59f-2ee73d0e3708 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=4de4bbcd-b1b8 -4482-8ef7-0d9b4a730e0c -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=def2c038-3b03 -4162-a563-a6ebec756f37 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=98a56425-4f88 -4f0f-963b-dada8dc0d8f8 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=d0570536-756e -4fda-883d-f2a3c4ac5bbd -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?FamilyID=2c7765a2-3117 -4dd8-94b4-0060ca16871b -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=0e72d0f1-2ce7 -4650-b72c-bb303351aafc -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=40d26d40-4203 -4013-b3f9-912a5b209fbd -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=3140527a-aa33 -462b-b3a6-bfcd78b5aa0c
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=6659fc40-71ee -44a9-9656-8d3ee02b5bc0 -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB9
http://www.microsoft.com/downloads/details.aspx?FamilyID=9ce1a721-0c6a -4775-9407-9633d817d716 -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=287e7921-8aab -42a6-b647-551d0a9adc15 -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=facab13f-ea31 -4c71-be4c-24e44ded174f -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=a253c19a-c808 -4115-8bd0-cf312d396abd
References
Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
References:
References:
- December 2009 Bulletin Release Advance Notification (Microsoft)
- Microsoft Internet Explorer Homepage (Microsoft)
- Microsoft Internet Explorer HTML Layout Engine Uninitialized Memory Vulnerabilit (iDefense Labs)
- Microsoft Security Advisory 977981 Released (Microsoft)
- Nortel Enterprise Response to Microsoft Security Bulletin MS09-072 (Nortel Networks)
- Code to mitigate IE STYLE zero-day ([email protected])
- IE7 ([email protected])
- Some more details on IE STYLE zero-day ([email protected])
- 2009009911, Rev 2 Nortel Enterprise Response to Security Bulletin MS09-072 (Nortel Networks)
- Microsoft Security Advisory (977981) (Microsoft)
- Microsoft Security Bulletin MS09-072 (Microsoft)
- Vulnerability Note VU#515749 Microsoft Internet Explorer CSS style element vulne (US-CERT)