Microsoft Internet Explorer CSS Race Condition Remote Code Execution Vulnerability
BID:37212
Info
Microsoft Internet Explorer CSS Race Condition Remote Code Execution Vulnerability
| Bugtraq ID: | 37212 |
| Class: | Race Condition Error |
| CVE: |
CVE-2009-3673 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2009 12:00AM |
| Updated: | Dec 14 2009 10:43PM |
| Credit: | An anonymous researcher working with TippingPoint and the Zero Day Initiative |
| Vulnerable: |
Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Peri Workstation 0 Nortel Networks Peri Application 0 Nortel Networks Multimedia Comm Mas 0 Nortel Networks Media Processing Svr 500 Rel 3.0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Nortel Networks Media Processing Svr 100 0 Nortel Networks Media Processing Server Nortel Networks Contact Center Multimedia & Outbound 7.0 Nortel Networks Contact Center Multimedia & Outbound 6.0 Nortel Networks Contact Center Multimedia Nortel Networks Contact Center Express Nortel Networks Contact Center Administration CCMA 7.0 Nortel Networks Contact Center Administration CCMA 6.0 Nortel Networks Contact Center Administration 0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 600r Nortel Networks CallPilot 202i Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1005r Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 8 Microsoft Internet Explorer 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CSS Race Condition Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the computer. Failed attacks may cause denial-of-service conditions.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the computer. Failed attacks may cause denial-of-service conditions.
Exploit / POC
Microsoft Internet Explorer CSS Race Condition Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Internet Explorer CSS Race Condition Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory along with fixes. Please see the references for details.
Microsoft Internet Explorer 7.0
Microsoft Internet Explorer 8
Solution:
The vendor has released an advisory along with fixes. Please see the references for details.
Microsoft Internet Explorer 7.0
-
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=7bdba030-e2c6 -44ac-bb5f-24ae8ec372a2 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 64-bit Itanium Edition (K
http://www.microsoft.com/downloads/details.aspx?FamilyID=72d44de7-dfc5 -4667-a59f-2ee73d0e3708 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=4de4bbcd-b1b8 -4482-8ef7-0d9b4a730e0c -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=def2c038-3b03 -4162-a563-a6ebec756f37 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=98a56425-4f88 -4f0f-963b-dada8dc0d8f8 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=d0570536-756e -4fda-883d-f2a3c4ac5bbd -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?FamilyID=2c7765a2-3117 -4dd8-94b4-0060ca16871b -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=0e72d0f1-2ce7 -4650-b72c-bb303351aafc -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=40d26d40-4203 -4013-b3f9-912a5b209fbd -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?FamilyID=3140527a-aa33 -462b-b3a6-bfcd78b5aa0c
Microsoft Internet Explorer 8
-
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB976325)
http://www.microsoft.com/downloads/details.aspx?familyid=0dd50357-64f2 -4286-86ba-c512e65eed2a -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?familyid=e62aba15-5eeb -46a2-a142-bfca94016c55 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP (KB976325)
http://www.microsoft.com/downloads/details.aspx?familyid=6c003629-77bf -4735-bd4a-c37c4386f869 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?familyid=0c9af3b5-d015 -4025-bbb4-1a5113e9113f -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB976325)
http://www.microsoft.com/downloads/details.aspx?familyid=5af3be0b-2dd2 -4039-90e1-2278e9c5aee5 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?familyid=9d9a04c8-a019 -4943-8e93-c6bfd77c8960 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB976325)
http://www.microsoft.com/downloads/details.aspx?familyid=43660133-43e1 -41f3-8a82-98c4a739914f -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Syste
http://www.microsoft.com/downloads/details.aspx?familyid=2c1b96f2-b3c3 -4711-a9ad-b2133ea7bf81 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?familyid=bcb38127-787f -49b0-b3fb-62f6a8628d89 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?familyid=22972970-740f -4c50-93ec-f6d49dd1b360 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB976325)
http://www.microsoft.com/downloads/details.aspx?familyid=47d5ada1-1d60 -4233-bdd3-64918b5e1245 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB976325)
http://www.microsoft.com/downloads/details.aspx?familyid=1e466b48-422f -4c80-8fdf-ba61111942b1
References
Microsoft Internet Explorer CSS Race Condition Remote Code Execution Vulnerability
References:
References:
- Microsoft Internet Explorer CSS Race Condition Code Execution Vulnerability (Zero Day Initiative)
- Microsoft Internet Explorer Homepage (Microsoft)
- Nortel Enterprise Response to Microsoft Security Bulletin MS09-072 (Nortel Networks)
- Microsoft Internet Explorer CSS Race Condition Code Execution Vulnerability (ZDI Disclosures
) - 2009009911, Rev 2 Nortel Enterprise Response to Security Bulletin MS09-072 (Nortel Networks)
- Microsoft Security Bulletin MS09-072 (Microsoft)