Microsoft Internet Explorer 'toStaticHTML' HTML Sanitizing Information Disclosure Vulnerability
BID:48199
Info
Microsoft Internet Explorer 'toStaticHTML' HTML Sanitizing Information Disclosure Vulnerability
| Bugtraq ID: | 48199 |
| Class: | Design Error |
| CVE: |
CVE-2011-1252 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2011 12:00AM |
| Updated: | Sep 13 2011 06:10PM |
| Credit: | Adi Cohen of IBM Rational Application Security; Trend Micro |
| Vulnerable: |
Microsoft SharePoint Services 64-bit 3.0 SP2 Microsoft SharePoint Services 3.0 SP2 Microsoft SharePoint Server 2010 Standard Edition 0 Microsoft SharePoint Server 2010 Enterprise Edition 0 Microsoft SharePoint Server 2010 SP1 Microsoft SharePoint Server 2007 x64 SP2 Microsoft SharePoint Server 2007 SP2 Microsoft SharePoint Foundation 2010 SP1 Microsoft SharePoint Foundation 2010 0 Microsoft Internet Explorer 8 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 7.0 Microsoft Groove Server 2010 SP1 Microsoft Groove Server 2010 0 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.2 SP2 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya Aura Conferencing 6.0 Standard |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer 'toStaticHTML' HTML Sanitizing Information Disclosure Vulnerability
Microsoft Internet Explorer is prone to an information-disclosure vulnerability that affects the 'toStaticHTML' API.
Attackers can exploit this issue to obtain sensitive information that may aid in further attacks.
Microsoft Internet Explorer is prone to an information-disclosure vulnerability that affects the 'toStaticHTML' API.
Attackers can exploit this issue to obtain sensitive information that may aid in further attacks.
Exploit / POC
Microsoft Internet Explorer 'toStaticHTML' HTML Sanitizing Information Disclosure Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
Solution / Fix
Microsoft Internet Explorer 'toStaticHTML' HTML Sanitizing Information Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Microsoft Internet Explorer 7.0
Microsoft Internet Explorer 8
Solution:
Vendor updates are available. Please see the references for details.
Microsoft Internet Explorer 7.0
-
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 241 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 64-bit Itanium Edition (K
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 239 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 255 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 264 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 253 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 254 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 for Itanium-based Systems
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 249 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 267 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 240 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 260
Microsoft Internet Explorer 8
-
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 250 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 261 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 249 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 271 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 252 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 259 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 268 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Syste
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 258 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 256 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 248 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2530548)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 245
References
Microsoft Internet Explorer 'toStaticHTML' HTML Sanitizing Information Disclosure Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)
- Microsoft Internet Explorer 'toStaticHTML' HTML Sanitizing Information Disclosu ([email protected])
- ASA-2011-179 MS11-050 Cumulative Security Update for Internet Explorer (2530548) (Avaya)
- Microsoft Security Bulletin MS11-050 - Critical Cumulative Security Update for I (Microsoft)
- Microsoft Security Bulletin MS11-074 - Important (Microsoft)