Microsoft Internet Explorer Local Resource Reference Vulnerability

BID:8886

Info

Microsoft Internet Explorer Local Resource Reference Vulnerability

Bugtraq ID: 8886
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Oct 24 2003 12:00AM
Updated: Oct 24 2003 12:00AM
Credit: The discovery of this vulnerability has been credited to "Mindwarper *" <[email protected]>.
Vulnerable: Microsoft Internet Explorer 6.0 SP1
Not Vulnerable:

Discussion

Microsoft Internet Explorer Local Resource Reference Vulnerability

Microsoft Internet Explorer is prone to an issue that may allow for unauthorized access to local resources. Internet Explorer version 6 SP1 imposed restrictions to limit remote sites from accessing local resources via file:// or res:// URIs (or other variants). It is reported that these restrictions may be bypassed by adding an additional slash when specifying a resource via one of these protocols.

This could aid in exploitation of other vulnerabilities, such as issues that permit an attacker to create files on a client system in a predictable location. Such content could then be referenced by an attacker using these protocols. The initial vulnerability report stated that the issue allowed for Zone Restriction Bypass via malformed IFRAMES. Additional technical information has been provided that contradicts the initial analysis. BID 8900 was created to describe the separate issue in Macromedia Flash.

Liu Die Yu has released conflicting information that states that this issue occurs because the user is redirected into a local resource and then the local resource is being refreshed. It is reported that other variations such as "file://" or "[DriveLetter]:\[...]" also work with this exploit. This is currently under investigation.

Exploit / POC

Microsoft Internet Explorer Local Resource Reference Vulnerability

Mindwarper has released a proof-of-concept for this issue which can be found at the following web site:

http://www.mlsecurity.com/ie/ie.htm

This proof-of-concept also exploits the issue described in BID 8900.

Liu Die Yu has provided an additional proof-of-concept:

http://www.safecenter.net/UMBRELLAWEBV4/IredirNrefresh/IredirNrefresh-MyPage.htm

Liu Die Yu has developed a proof of concept exploit to demonstrate arbitrary code execution using a combination of unpatched Internet Explorer vulnerabilities. Successful exploitation of these vulnerabilities combines results in the execution of a cached executable file supplied by an attacker. The issues known to be exploited in cobmination with the issue described in this BID, are described in the following BIDs:

BID 8980 - Microsoft Internet Explorer Double Slash Cache Zone Bypass Vulnerability
BID 8577 - Multiple Microsoft Internet Explorer Script Execution Vulnerabilities
BID 3779 - Microsoft Internet Explorer JavaScript Local File Enumeration Vulnerability

The exploit can be obtained by visiting the following demo page provided by Liu Die Yu or by downloading execdror5-Demo.zip below.

http://www.safecenter.net/UMBRELLAWEBV4/execdror5/execdror5-MyPage.htm

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report