Internet Explorer CVE-2010-0249 'srcElement()' Remote Code Execution Vulnerability
BID:37815
Info
Internet Explorer CVE-2010-0249 'srcElement()' Remote Code Execution Vulnerability
| Bugtraq ID: | 37815 |
| Class: | Unknown |
| CVE: |
CVE-2010-0249 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2010 12:00AM |
| Updated: | Feb 03 2010 09:01PM |
| Credit: | This issue was discovered in the wild; Microsoft credits Meron Sellem of BugSec. |
| Vulnerable: |
Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri CTI 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Self-Service CDD 0 Nortel Networks Self Service - CDD 0 Nortel Networks Peri Workstation 0 Nortel Networks Peri Application 0 Nortel Networks Media Processing Svr 500 Rel 3.0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Nortel Networks Media Processing Svr 100 0 Nortel Networks Media Processing Server Nortel Networks Contact Center Multimedia & Outbound 7.0 Nortel Networks Contact Center Multimedia & Outbound 6.0 Nortel Networks Contact Center Express Nortel Networks Contact Center Administration CCMA 7.0 Nortel Networks Contact Center Administration CCMA 6.0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 600r Nortel Networks CallPilot 202i Nortel Networks CallPilot 201i Nortel Networks CallPilot 1005r Microsoft Internet Explorer 8 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Internet Explorer CVE-2010-0249 'srcElement()' Remote Code Execution Vulnerability
Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the browser. Successful exploits will compromise the application and possibly the computer. Failed attacks will cause denial-of-service conditions.
Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the browser. Successful exploits will compromise the application and possibly the computer. Failed attacks will cause denial-of-service conditions.
Exploit / POC
Internet Explorer CVE-2010-0249 'srcElement()' Remote Code Execution Vulnerability
This issue is being actively exploited in the wild in targeted attacks.
Immunity has reportedly developed and released a private exploit for Internet Explorer 7 and 8 that can bypass DEP and ASLR protections. The exploit was released as part of Immunity's CANVAS Early Update service and is not otherwise publicly available or known to be circulating in the wild.
The following exploit and Metasploit exploit module are available:
This issue is being actively exploited in the wild in targeted attacks.
Immunity has reportedly developed and released a private exploit for Internet Explorer 7 and 8 that can bypass DEP and ASLR protections. The exploit was released as part of Immunity's CANVAS Early Update service and is not otherwise publicly available or known to be circulating in the wild.
The following exploit and Metasploit exploit module are available:
Solution / Fix
Internet Explorer CVE-2010-0249 'srcElement()' Remote Code Execution Vulnerability
Solution:
A vendor advisory and updates are available; please see the references for more information.
Microsoft Internet Explorer 7.0
Microsoft Internet Explorer 8
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
Solution:
A vendor advisory and updates are available; please see the references for more information.
Microsoft Internet Explorer 7.0
-
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=14726445-3ff4 -463c-9fc1-c9b758079aca -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 64-bit Itanium Edition (K
http://www.microsoft.com/downloads/details.aspx?FamilyID=5622f223-df9c -4a6a-bdf0-feebaf9920fd -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=c8742230-16d8 -4b2f-bd3e-8834c759856b -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=3510c7d8-7e8f -479e-b6f9-5745a845664d -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=cc5aea0b-e553 -4f7f-a2cc-cba41bb87ae7 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=8c4c91ec-1b2b -4176-bd77-45245b590329 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?FamilyID=9395547f-b620 -4cbd-9ff5-11b76cd73859 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=4f9975b8-3f91 -4116-9200-ef55ece75854 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=92495551-dedd -43d4-bb3a-51028bc5c6d6 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=3cb139b3-59f4 -44ef-9911-4dd4e3b83e7d
Microsoft Internet Explorer 8
-
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=7d480c87-2ca9 -4505-a59d-a6d73d001fa5 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=3e2e740b-8417 -4758-8468-15221249ec71 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=7c2948fb-f486 -4801-bc21-bbf40d5a78c2 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=41b83fad-948b -4a9c-80ed-9c5a60bd35b4 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=278443c1-15dc -436b-893b-ffea6d29d16d -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=a584cd0f-2e05 -4e36-8858-0ffead637162 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=f5ce8582-af63 -4870-bee3-0abeeefa1458 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Syste
http://www.microsoft.com/downloads/details.aspx?familyid=9d137bab-8312 -4240-af74-c65ba652fde0 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=d3386793-a594 -4bc5-8308-28b561d43087 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=be11981c-d286 -4e3c-94bf-d4e67a975d5a -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=5e2cbd7d-f64f -49e5-a159-1965ebfe2a92 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?familyid=b7a7e8e7-f4c5 -459d-ab6c-05a192e1e3f9
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Update for Internet Explorer 6 SP1 (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=a38aa9d0-c3fe -4d41-8805-7d5370263c1b
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=fea91227-44ad -4549-8732-497a8ceff870 -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB9
http://www.microsoft.com/downloads/details.aspx?FamilyID=b9308d50-ca66 -43ff-9dc5-d05c90baa764 -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=633e63f4-605b -43c4-8a4b-2730312a1c72 -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=207eecad-6e84 -48e6-ae18-6794a3618ee0 -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP x64 Edition (KB978207)
http://www.microsoft.com/downloads/details.aspx?FamilyID=eb2d8055-4d50 -4f83-82b8-055c7b8f5422
References
Internet Explorer CVE-2010-0249 'srcElement()' Remote Code Execution Vulnerability
References:
References:
- 21.01.10 Internet Explorer CVE-2010-0249 Remote Code Execution Vulnerability (BugSec)
- Advisory 979352 Update for Monday January 18 (Microsoft)
- ASLR+DEP = no problem. :> (Dave Aitel)
- Avaya Enterprise (Fomerly Nortel Enterprise) Response to Microsoft Security Bull (Nortel Networks)
- Further Insight into Security Advisory 979352 and the Threat Landscape (Microsoft)
- Internet Explorer Homepage (Microsoft)
- Reproducing the 'Aurora' IE Exploit (Metasploit)
- Security Advisory 979352 �?? Going out of Band (Microsoft Security Response Center)
- Security Advisory 979352 Released (Microsoft Security Response Center)
- ASA-2010-018 MS10-002 Cumulative Security Update for Internet Explorer (978207) (Avaya)
- Microsoft Security Advisory (979352) Vulnerability in Internet Explorer Could Al (Microsoft)
- Microsoft Security Bulletin MS10-002 (Microsoft)
- Vulnerability Note VU#492515 Microsoft Internet Explorer allows remote code exec (US-CERT)