Microsoft Internet Explorer Local Resource Reference Vulnerability
BID:8886
Info
Microsoft Internet Explorer Local Resource Reference Vulnerability
| Bugtraq ID: | 8886 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2003 12:00AM |
| Updated: | Oct 24 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to "Mindwarper *" <[email protected]>. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Local Resource Reference Vulnerability
Microsoft Internet Explorer is prone to an issue that may allow for unauthorized access to local resources. Internet Explorer version 6 SP1 imposed restrictions to limit remote sites from accessing local resources via file:// or res:// URIs (or other variants). It is reported that these restrictions may be bypassed by adding an additional slash when specifying a resource via one of these protocols.
This could aid in exploitation of other vulnerabilities, such as issues that permit an attacker to create files on a client system in a predictable location. Such content could then be referenced by an attacker using these protocols. The initial vulnerability report stated that the issue allowed for Zone Restriction Bypass via malformed IFRAMES. Additional technical information has been provided that contradicts the initial analysis. BID 8900 was created to describe the separate issue in Macromedia Flash.
Liu Die Yu has released conflicting information that states that this issue occurs because the user is redirected into a local resource and then the local resource is being refreshed. It is reported that other variations such as "file://" or "[DriveLetter]:\[...]" also work with this exploit. This is currently under investigation.
Microsoft Internet Explorer is prone to an issue that may allow for unauthorized access to local resources. Internet Explorer version 6 SP1 imposed restrictions to limit remote sites from accessing local resources via file:// or res:// URIs (or other variants). It is reported that these restrictions may be bypassed by adding an additional slash when specifying a resource via one of these protocols.
This could aid in exploitation of other vulnerabilities, such as issues that permit an attacker to create files on a client system in a predictable location. Such content could then be referenced by an attacker using these protocols. The initial vulnerability report stated that the issue allowed for Zone Restriction Bypass via malformed IFRAMES. Additional technical information has been provided that contradicts the initial analysis. BID 8900 was created to describe the separate issue in Macromedia Flash.
Liu Die Yu has released conflicting information that states that this issue occurs because the user is redirected into a local resource and then the local resource is being refreshed. It is reported that other variations such as "file://" or "[DriveLetter]:\[...]" also work with this exploit. This is currently under investigation.
Exploit / POC
Microsoft Internet Explorer Local Resource Reference Vulnerability
Mindwarper has released a proof-of-concept for this issue which can be found at the following web site:
http://www.mlsecurity.com/ie/ie.htm
This proof-of-concept also exploits the issue described in BID 8900.
Liu Die Yu has provided an additional proof-of-concept:
http://www.safecenter.net/UMBRELLAWEBV4/IredirNrefresh/IredirNrefresh-MyPage.htm
Liu Die Yu has developed a proof of concept exploit to demonstrate arbitrary code execution using a combination of unpatched Internet Explorer vulnerabilities. Successful exploitation of these vulnerabilities combines results in the execution of a cached executable file supplied by an attacker. The issues known to be exploited in cobmination with the issue described in this BID, are described in the following BIDs:
BID 8980 - Microsoft Internet Explorer Double Slash Cache Zone Bypass Vulnerability
BID 8577 - Multiple Microsoft Internet Explorer Script Execution Vulnerabilities
BID 3779 - Microsoft Internet Explorer JavaScript Local File Enumeration Vulnerability
The exploit can be obtained by visiting the following demo page provided by Liu Die Yu or by downloading execdror5-Demo.zip below.
http://www.safecenter.net/UMBRELLAWEBV4/execdror5/execdror5-MyPage.htm
Mindwarper has released a proof-of-concept for this issue which can be found at the following web site:
http://www.mlsecurity.com/ie/ie.htm
This proof-of-concept also exploits the issue described in BID 8900.
Liu Die Yu has provided an additional proof-of-concept:
http://www.safecenter.net/UMBRELLAWEBV4/IredirNrefresh/IredirNrefresh-MyPage.htm
Liu Die Yu has developed a proof of concept exploit to demonstrate arbitrary code execution using a combination of unpatched Internet Explorer vulnerabilities. Successful exploitation of these vulnerabilities combines results in the execution of a cached executable file supplied by an attacker. The issues known to be exploited in cobmination with the issue described in this BID, are described in the following BIDs:
BID 8980 - Microsoft Internet Explorer Double Slash Cache Zone Bypass Vulnerability
BID 8577 - Multiple Microsoft Internet Explorer Script Execution Vulnerabilities
BID 3779 - Microsoft Internet Explorer JavaScript Local File Enumeration Vulnerability
The exploit can be obtained by visiting the following demo page provided by Liu Die Yu or by downloading execdror5-Demo.zip below.
http://www.safecenter.net/UMBRELLAWEBV4/execdror5/execdror5-MyPage.htm