[ insider_reports_insider ] IE6 Not Forgotten By Attackers
David Utter Staff Writer
2006-11-02
Insider Reports RSS Feed
Internet Explorer 7 has been available for a few days, but with millions of installations of IE6 in the world there are plenty of PCs that have not opted for the latest release from Microsoft.
 | | "Forget Me Not" |  |
News about the WScript.Shell problem popped up on the Handler's Diary operated by the SANS Institute.
When exploited, the flaw in IE6 could permit the execution of arbitrary code at the permission level of the user.
Winguides said "the WScript.Shell object provides functions to read system information and environment variables, work with the registry and manage shortcuts."
The initial advisory appeared on the Bugtraq mailing list. It included a description of the exploit, and proof of concept code demonstrating how it functions. Bugtraq does not list IE7 as being vulnerable to the problem.
Networking company Cisco also discussed the issue in more detail, and pegged it to a problem with WScript.Shell:
An unauthenticated, remote attacker can create malicious JavaScript that causes the object to execute code with the privileges of the user. This code could be placed on a malicious web page. The attacker would then need to convince the user to visit the malicious web page with a vulnerable version of Internet Explorer.
Even though the vulnerability has been discussed online since earlier in the week, Microsoft has not commented on it in their Security Response Center blog.
WScript.Shell has posed problems previously as part of other exploits, like one revealed in July 2006 that could have been attacked through WScript.Shell.
Microsoft has addressed another problem, this time with a vulnerability in Visual Studio.
A critical vulnerability in the program could permit remote code execution and system control by a malicious party.
Workarounds for the problematic ActiveX control, the WMI Object Broker, has been posted as part of Microsoft's security advisory on the issue.
Though the workarounds don't correct the problem, they do block potential avenues of attack aimed at the uncorrected vulnerability.
---
Tags: Microsoft, Internet Explorer
Add to Del.icio.us | Digg | Reddit | Furl
Get all the updates -
About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.
More insider_reports_insider Articles
Insider Reports RSS Feed
|
|