MS-ISAC ADVISORY NUMBER:
2009-033
DATE(S) ISSUED:
6/9/2009
SUBJECT:
Multiple Vulnerabilities in Internet Explorer
Eight vulnerabilities have been discovered in Microsoft's web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
SYSTEMS AFFECTED:
- Microsoft Internet Explorer 5.01 Service Pack 4
- Microsoft Internet Explorer 6
- Microsoft Internet Explorer 7
- Microsoft Internet Explorer 8
RISK:
Government:
Large and medium government entities: High
Small government entities: High
Businesses:
Large and medium business entities: High
Small business entities: High
Home users: High
DESCRIPTION:
Eight vulnerabilities have been discovered in Microsoft Internet Explorer. Details of these vulnerabilities are as follows:
Race Condition Cross-Domain Information Disclosure Vulnerability
An information disclosure vulnerability exists in the way Internet Explorer identifies the domain of an executed script. An attacker could exploit this vulnerability to access local files or content from a browser window in another domain or Internet zone by convincing the user to visit a specially crafted web page.
Cross-Domain Information Disclosure Vulnerability
An information disclosure vulnerability exists in the way Internet Explorer caches data and incorrectly allows the content to be rendered as HTML. An attacker could exploit this vulnerability to access local files or content from a browser window in another domain or Internet zone by convincing the user to visit a specially crafted web page.
DHTML Object Memory Corruption Vulnerability
A remote code execution vulnerability exists in the way Internet Explorer handles certain method calls to HTML objects. As a result, system memory may be corrupted in such a way that an attacker could execute arbitrary code if a user visits a specially crafted web site.
HTML Objects Memory Corruption Vulnerability
A remote code execution vulnerability exists in the way Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit this vulnerability by constructing a specially crafted web page. When a user views the Web page, the vulnerability could allow remote code execution.
Uninitialized Memory Corruption Vulnerability
Four remote code execution vulnerabilities exist in the way Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit these vulnerabilities by constructing a specially crafted web page. When a user views the Web page, the vulnerability could allow remote code execution.
Successful exploitation could allow an attacker to execute arbitrary code on the affected system. Depending on the privileges associated with the user, the attacker could then install programs; view, change, or delete data; or create new accounts with full privileges. In the case of information disclosure, the attacker could steal sensitive information.
RECOMMENDATIONS:
We recommend the following actions be taken:
- Apply appropriate patches provided by Microsoft to vulnerable systems immediately after appropriate testing.
- Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack.
- Do not visit un-trusted websites or follow links provided by unknown or un-trusted sources.
- Do not download or open files from un-trusted websites.
REFERENCES:
Microsoft:
http://www.microsoft.com/technet/security/bulletin/MS09-019.mspx
Security Focus:
http://www.securityfocus.com/bid/35198
http://www.securityfocus.com/bid/35200
http://www.securityfocus.com/bid/35222
http://www.securityfocus.com/bid/35223
http://www.securityfocus.com/bid/35224
http://www.securityfocus.com/bid/35234
http://www.securityfocus.com/bid/35235
CVE:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3091
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1140
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1141
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1528
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1529
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1530
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1531
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1532
This cyber advisory was issued by the Multi-State Information Sharing and Analysis Center (MS-ISAC) and was intended for government entities. The information may or may not be applicable to the general public and accordingly, the MS-ISAC does not warrant its use for any specific purposes.
