Saturday, July 31, 2004

Unscheduled Security Update Fixes Critical IE Flaws

Unscheduled Security Update Fixes Critical IE Flaws:
"The security bulletin accompanying the updates, numbered MS04-025, addresses three vulnerabilities rated 'critical' that could result in an attacker executing code in the context of a logged-on user. If the user is logged on as Administrator, the attack would have free reign over the system."

The first vulnerability, titled "Navigation Method Cross-Domain Vulnerability," could allow an attacker to execute arbitrary code in the Local Machine security zone. Microsoft reports that many factors can make this vulnerability more difficult to execute, including installing certain previous updates. Nevertheless, Symantec reports this as the most critical of the three vulnerabilities and that they have already seen exploits of it in the wild.

The other two vulnerabilities are related to the browser's handling of image files. Both are buffer overflows in Internet Explorer's handling of these files, one for BMP files and one for GIF files. Internet Explorer 6 Service Pack 1 and Windows Server 2003, both 32-bit and 64-bit editions, are not affected by the BMP file vulnerability.

The GIF buffer overrun affects all versions of Windows and Internet Explorer and results when the attacker attempts to free memory that has already been freed. The bulletin indicates that this is most likely a denial-of-service attack, but the potential exists for it to be used to execute arbitrary code.

The update replaces a previous update, MS04-004. If users have applied that patch and subsequently applied non-public hotfixes they may have to reapply them after applying the new cumulative update. Users should consult the bulletin and Microsoft support.

http://www.microsoft.com/technet/security/bulletin/MS04-025.mspx

http://www.eweek.com/article2/0,1759,1629584,00.asp

No comments: