Multiple Microsoft Internet Explorer Script Execution Vulnerabilities
BID:8577
Info
Multiple Microsoft Internet Explorer Script Execution Vulnerabilities
| Bugtraq ID: | 8577 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2003 12:00AM |
| Updated: | Sep 10 2003 12:00AM |
| Credit: | Discovery credited to Liu Die Yu and Jelmer. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Exploit / POC
Multiple Microsoft Internet Explorer Script Execution Vulnerabilities
Liu Die Yu has developed a proof of concept exploit to demonstrate arbitrary code execution using a combination of unpatched Internet Explorer vulnerabilities. Successful exploitation of these vulnerabilities combines results in the execution of a cached executable file supplied by an attacker. The issues known to be exploited in cobmination the issue described in this BID (specifically the WsOpenFileJPU bug), are described in the following BIDs:
BID 8980 - Microsoft Internet Explorer Double Slash Cache Zone Bypass Vulnerability
BID 8886 - Microsoft Internet Explorer Local Resource Reference Vulnerability
BID 3779 - Microsoft Internet Explorer JavaScript Local File Enumeration Vulnerability
The exploit can be obtained by visiting the following demo page provided by Liu Die Yu or by downloading execdror5-Demo.zip below.
http://www.safecenter.net/UMBRELLAWEBV4/execdror5/execdror5-MyPage.htm
*** The ADODB.Stream Object exploit that was previously mentioned in this BID has been assigned its own BID (10514). Please refer to that BID for further information.
Liu Die Yu has developed a proof of concept exploit to demonstrate arbitrary code execution using a combination of unpatched Internet Explorer vulnerabilities. Successful exploitation of these vulnerabilities combines results in the execution of a cached executable file supplied by an attacker. The issues known to be exploited in cobmination the issue described in this BID (specifically the WsOpenFileJPU bug), are described in the following BIDs:
BID 8980 - Microsoft Internet Explorer Double Slash Cache Zone Bypass Vulnerability
BID 8886 - Microsoft Internet Explorer Local Resource Reference Vulnerability
BID 3779 - Microsoft Internet Explorer JavaScript Local File Enumeration Vulnerability
The exploit can be obtained by visiting the following demo page provided by Liu Die Yu or by downloading execdror5-Demo.zip below.
http://www.safecenter.net/UMBRELLAWEBV4/execdror5/execdror5-MyPage.htm
*** The ADODB.Stream Object exploit that was previously mentioned in this BID has been assigned its own BID (10514). Please refer to that BID for further information.
Solution / Fix
Multiple Microsoft Internet Explorer Script Execution Vulnerabilities
Solution:
Three of the issues described in this BID have been addressed with the release of MS03-048, which includes patches for three domain violation vulnerabilities (in addition to other issues) in Internet Explorer. These specific issues are covered individually in BIDs 9013, 9014 and 9015. Further fix information can be found in the MS03-048 as well as the appropriate BIDs.
The other issues described in this BID do not presently appear to be addressed. This BID will be updated as more information is made available.
Solution:
Three of the issues described in this BID have been addressed with the release of MS03-048, which includes patches for three domain violation vulnerabilities (in addition to other issues) in Internet Explorer. These specific issues are covered individually in BIDs 9013, 9014 and 9015. Further fix information can be found in the MS03-048 as well as the appropriate BIDs.
The other issues described in this BID do not presently appear to be addressed. This BID will be updated as more information is made available.