Microsoft Internet Explorer 8 'toStaticHTML()' HTML Sanitization Bypass Weakness
BID:42467
Info
Microsoft Internet Explorer 8 'toStaticHTML()' HTML Sanitization Bypass Weakness
| Bugtraq ID: | 42467 |
| Class: | Design Error |
| CVE: |
CVE-2010-3324 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2010 12:00AM |
| Updated: | Apr 19 2013 02:39AM |
| Credit: | Mario Heiderich, Web Sec |
| Vulnerable: |
Microsoft SharePoint Services 64-bit 3.0 SP2 Microsoft SharePoint Services 64-bit 3.0 SP1 Microsoft SharePoint Services 64-bit 3.0 Microsoft SharePoint Services 64-bit 3.0 Microsoft SharePoint Services 3.0 SP2 Microsoft SharePoint Services 3.0 SP1 Microsoft SharePoint Server 2007 x64 SP2 Microsoft SharePoint Server 2007 x64 SP1 Microsoft SharePoint Server 2007 x64 0 Microsoft SharePoint Server 2007 Standard Edition 0 Microsoft SharePoint Server 2007 Enterprise Edition 0 Microsoft SharePoint Server 2007 SP2 Microsoft SharePoint Server 2007 SP1 Microsoft SharePoint Server 2007 0 Microsoft SharePoint Foundation 2010 0 Microsoft Internet Explorer 8 Microsoft Groove Server 2010 0 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Communication Server 1000 Telephony Manager 0 Avaya CallPilot 0 Avaya Aura Conferencing Standard Avaya Aura Conferencing 6.0 Standard |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer 8 'toStaticHTML()' HTML Sanitization Bypass Weakness
Internet Explorer 8 is prone to a security-bypass weakness.
Internet Explorer 8 includes a method designed to sanitize executable script constructs from HTML. Attackers can bypass this protection, allowing script code to execute on the client, for example in a 'postMessage' call.
Attackers can leverage this issue to obtain sensitive information or potentially launch cross-site scripting attacks on unsuspecting users of targeted sites. Other attacks may also be possible.
Internet Explorer 8 is prone to a security-bypass weakness.
Internet Explorer 8 includes a method designed to sanitize executable script constructs from HTML. Attackers can bypass this protection, allowing script code to execute on the client, for example in a 'postMessage' call.
Attackers can leverage this issue to obtain sensitive information or potentially launch cross-site scripting attacks on unsuspecting users of targeted sites. Other attacks may also be possible.
Exploit / POC
Microsoft Internet Explorer 8 'toStaticHTML()' HTML Sanitization Bypass Weakness
To exploit this issue, an attacker must entice an unsuspecting user into following a malicious URI.
The following example code is available:
To exploit this issue, an attacker must entice an unsuspecting user into following a malicious URI.
The following example code is available:
Solution / Fix
Microsoft Internet Explorer 8 'toStaticHTML()' HTML Sanitization Bypass Weakness
Solution:
The vendor has released advisories and updates. Please see the references for details.
Microsoft SharePoint Services 3.0 SP2
Microsoft Groove Server 2010 0
Microsoft SharePoint Services 64-bit 3.0 SP2
Microsoft Internet Explorer 8
Microsoft SharePoint Server 2007 x64 SP2
Microsoft SharePoint Foundation 2010 0
Microsoft SharePoint Server 2007 SP2
Solution:
The vendor has released advisories and updates. Please see the references for details.
Microsoft SharePoint Services 3.0 SP2
-
Microsoft wss-kb2345304-fullfile-x86-glb.exe
http://www.microsoft.com/downloads/details.aspx?familyid=12fd97a9-6fb8 -4b65-a497-a56587f114e1
Microsoft Groove Server 2010 0
-
Microsoft grooveserver2010-kb2346298-fullfile-x64-glb.exe
http://www.microsoft.com/downloads/details.aspx?familyid=e032aef8-dd30 -41c6-99bb-8cf0491451cc
Microsoft SharePoint Services 64-bit 3.0 SP2
-
Microsoft wss-kb2345304-fullfile-x64-glb.exe
http://www.microsoft.com/downloads/details.aspx?familyid=58d1e91d-a037 -485d-a6d9-80fbf403b108
Microsoft Internet Explorer 8
-
Microsoft IE8-Windows6.0-KB2360131-x64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=adeb3036-62fa -4a29-b82f-ff4a50c05996 -
Microsoft IE8-Windows6.0-KB2360131-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=191c8388-f1ef -45b6-9f07-d5654a973abe -
Microsoft IE8-WindowsServer2003-KB2360131-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=9af37f62-5585 -4ff5-9dd3-3fa0b148ae08 -
Microsoft IE8-WindowsServer2003.WindowsXP-KB2360131-x64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=05413f6c-b4be -4892-b4b3-c54dd01fd95d -
Microsoft IE8-WindowsXP-KB2360131-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=93580299-d764 -417f-a7fa-ee441fea2bb3 -
Microsoft Windows6.1-KB2360131-ia64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=bbaa9f46-8fc7 -4c44-b38c-dc3d5210f63d -
Microsoft Windows6.1-KB2360131-x64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=ffe364ee-e2ae -466c-b727-14b1a976a860 -
Microsoft Windows6.1-KB2360131-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=6595770f-e580 -4613-a83a-3b8ee4cc30f1
Microsoft SharePoint Server 2007 x64 SP2
-
Microsoft office2007-kb2345212-fullfile-x64-glb.exe
http://www.microsoft.com/downloads/details.aspx?familyid=e5e60751-242a -4fdb-9852-6d94050d3d0e
Microsoft SharePoint Foundation 2010 0
-
Microsoft spf2010-kb2345322-fullfile-x64-glb.exe
http://www.microsoft.com/downloads/details.aspx?familyid=fc146fcb-c2cb -4860-a0cd-4b09fa3f44eb
Microsoft SharePoint Server 2007 SP2
-
Microsoft office2007-kb2345212-fullfile-x86-glb.exe
http://www.microsoft.com/downloads/details.aspx?familyid=aee3f2de-ccf3 -4d32-b468-eede4e8afcd4
References
Microsoft Internet Explorer 8 'toStaticHTML()' HTML Sanitization Bypass Weakness
References:
References:
- IE8 toStaticHtml Bypass (Web Sec
) - Internet Explorer Homepage (Microsoft)
- Safer Mashups: HTML Sanitization (Eric Lawrence)
- ASA-2010-278 MS10-071 Cumulative Security Update for Internet Explorer (2360131) (Avaya)
- Microsoft Security Bulletin MS10-071 (Microsoft)
- Microsoft Security Bulletin MS10-072 (Microsoft)