MS03-015 : Cumulative Patch for Internet Explorer


Recommended Posts

-----BEGIN PGP SIGNED MESSAGE-----

- -------------------------------------------------------------------

Title: Cumulative Patch for Internet Explorer (813489)

Date: 23 April 2003

Software: Microsoft © Internet Explorer

Impact: Run code of the attacker's choice on a user's machine.

Max Risk: Critical

Bulletin: MS03-015

Microsoft encourages customers to review the Security Bulletins at:

http://www.microsoft.com/technet/security/...in/MS03-015.asp

http://www.microsoft.com/security/security...ns/ms03-015.asp

- -------------------------------------------------------------------

Issue:

======

This is a cumulative patch that includes the functionality of all

previously released patches for Internet Explorer 5.01, 5.5 and

6.0. In addition, it eliminates the following four newly discovered

vulnerabilities:

- -A buffer overrun vulnerability in URLMON.DLL that occurs because

Internet Explorer does not correctly check the parameters of

information being received from a web server. It could be possible

for an attacker to exploit this vulnerability to run arbitrary code

on a user's system. A user simply visiting an attacker's website

could allow the attacker to exploit the vulnerability without any

other user action.

- -A vulnerability in the Internet Explorer file upload control that

allows input from a script to be passed to the upload control. This

vulnerability could allow an attacker to supply a file name to the

file upload control and automatically upload a file from the user's

system to a web server.

- -A flaw in the way Internet Explorer handles the rendering of third

party files. The vulnerability results because the Internet

Explorer method for rendering third party file types does not

properly check parameters passed to it. An attacker could create a

specially formed URL that would inject script during the rendering

of a third party file format and cause the script to execute in the

security context of the user.

- -A flaw in the way modal dialogs are treated by Internet Explorer

that occurs because an input parameter is not properly checked.

This flaw could allow an attacker to use an injected script to

provide access to files stored on a user's computer. Although a

user who visited the attacker's website could allow the attacker to

exploit the vulnerability without any other user action, an

attacker would have no way to force the user to visit the website.

In addition to eliminating the above vulnerabilities, this patch

also includes a fix for Internet Explorer 6.0 SP1 that corrects the

method by which Internet Explorer displays help information in the

local computer zone. While we are not aware of a method to exploit

this vulnerability by itself, if it were possible to exploit it, it

could allow an attacker to read local files on a visiting user's

system.

This patch also sets the Kill Bit on the Plugin.ocx ActiveX control

which has a security vulnerability. This killbit has been set in

order to ensure that the vulnerable control cannot be reintroduced

onto users' systems and to ensure that users who already have the

vulnerable control on their system are protected. This issue is

discussed further in Microsoft Knowledge Base Article 813489.

Like the previous Internet Explorer cumulative patch released with

bulletin MS03-004, this cumulative patch will cause

window.showHelp( ) to cease to function if you have not applied the

HTML Help update. If you have installed the updated HTML Help

control from Knowledge Base article 811830, you will still be able

to use HTML Help functionality after applying this patch.

Mitigating factors:

====================

There are common mitigating factors across all of the

vulnerabilities:

- -The attacker would have to host a web site that contained a web

page used to exploit the particular vulnerability.

- -By default, Outlook Express 6.0 and Outlook 2002 open HTML mails

in the Restricted Sites Zone. In addition, Outlook 98 and 2000 open

HTML mails in the Restricted Sites Zone if the Outlook Email

Security Update has been installed. Customers who use any of these

products would be at no risk from an e-mail borne attack that

attempted to automatically exploit these vulnerabilities. The

attacker would have no way to force users to visit a malicious web

site. Instead, the attacker would need to lure them there,

typically by getting them to click on a link that would take them

to the attacker's site.

In addition to the common factors, there are a number of individual

mitigating factors:

URLMON.DLL Buffer Overrun:

- -Code that executed on the system would only run under the

privileges of the locally logged in user.

File Upload Control vulnerability:

- -The attacker would have to know the explicit path and name of the

file to be uploaded in advance.

Third Party plug-in rendering:

- -The third party plugin would have to be present on the user's

system in order for it to be exploited

Risk Rating:

============

- Critical

Patch Availability:

===================

- A patch is available to fix this vulnerability. Please read the

Security Bulletins at

http://www.microsoft.com/technet/security/...in/ms03-015.asp

http://www.microsoft.com/security/security...ns/ms03-015.asp

for information on obtaining this patch.

- ----------------------------------------------------------------

Edited by xStainDx
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Oddly, there was a time that UFC games were culturally relevant, largely because of the graphics and gameplay that was different than the norm. But it seems like as the sport grew in popularity, gaming outlets stopped talking about the games.
    • Microsoft Edge 149.0.4022.69 by Razvan Serea Microsoft Edge is a super fast and secure web browser from Microsoft. It works on almost any device, including PCs, iPhones and Androids. It keeps you safe online, protects your privacy, and lets you browse the web quickly. You can even use it on all your devices and keep your browsing history and favorites synced up. Built on the same technology as Chrome, Microsoft Edge has additional built-in features like Startup boost and Sleeping tabs, which boost your browsing experience with world class performance and speed that are optimized to work best with Windows. Microsoft Edge security and privacy features such as Microsoft Defender SmartScreen, Password Monitor, InPrivate search, and Kids Mode help keep you and your loved ones protected and secure online. Microsoft Edge has features to keep both you and your family protected. Enable content filters and access activity reports with your Microsoft Family Safety account and experience a kid-friendly web with Kids Mode. The new Microsoft Edge is now compatible with your favorite extensions, so it’s easy to personalize your browsing experience. Microsoft Edge 149.0.4022.69 changelog: Fixed an issue that caused the Downloads dialog to continue displaying the "Keep/Delete" prompt for .rdp files after the download completed. Stable channel security updates are listed here. Download: Microsoft Edge (64-bit) | 193.0 MB (Freeware) Download: Microsoft Edge (32-bit) | 170.0 MB Download: Microsoft Edge (ARM64) | 188.0 MB View: Microsoft Edge Website | Release History Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Save 44% on Intuit QuickBooks Desktop Pro Plus 2024 (1 User for 1-Year) by Steven Parker Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where for only a limited time, you can save 44% on Intuit QuickBooks Desktop Pro Plus 2024 (1 User + 1 Year) for Windows. Take control of your business finances with Intuit® QuickBooks® Desktop Pro Plus 2024 Lifetime Activation for Windows. This powerful accounting software simplifies bookkeeping, expense tracking, invoicing, and financial management—all in one intuitive platform. Designed for small business owners, freelancers, and accountants, QuickBooks® Desktop Pro Plus 2024 ensures accuracy, efficiency, and seamless transaction tracking. Stay organized, save time, and manage your finances with confidence—no subscriptions, just lifetime access! Financial and business management Comprehensive Financial Management: Gain access to a full suite of features designed to handle everything from creating invoices & managing expenses to generating reports and tracking sales. Enhanced Reporting Tools: Generate professional reports & insights to make informed financial decisions and help you stay ahead of your business goals. Job Costing: Track the profitability of specific jobs or projects. Fixed Asset Management: Track the depreciation & value of fixed assets. Customer & Vendor Management: Organize information, streamline communication & enhance customer relations. Sales Order Processing: Create & manage sales orders from start to finish. Purchase Order Processing: Create & manage purchase orders to streamline vendor payments. Improved Inventory Management: Enhanced features for tracking inventory levels & costs. Automation, integration, and support Enhanced Bank Feeds: Web Connect (manual QBO imports), works on all licenses for easier bank reconciliation Time Tracking: Track employee time to accurately calculate payroll and project costs Easy Data Import: Quickly transfer financial data from Excel or older QuickBooks® versions Why choose Intuit® QuickBooks® Desktop Pro Plus 2024? Effortless Installation: Quick and easy setup with step-by-step guidance. No Hidden Costs: One-time payment—no subscriptions or recurring fees. Direct Official Download: Access the software securely from the official QuickBooks® website. Stay Up to Date: Get the latest updates and features for optimal performance. Multilingual Support: Available in multiple languages to suit your needs. Lifetime Access: A one-time purchase means no ongoing costs. IMPORTANT: Cloud integrations (QuickBooks Payments, TurboTax, and Online logins) are NOT included. Good to know: Length of access: lifetime Redemption deadline: redeem your code within 30 days of purchase Access options: Windows Max number of device(s): 2 (for 1 user only and can't be used simultaneously) Version: 2024 (United States) 64-bit Available to both NEW and EXISTING users For US customers only Updates included An Intuit QuickBooks Desktop Pro Plus 2024 (1 User + 1-Year) for Windows: Lifetime License normally costs $536, but it can be yours for just $299.99 for a limited time, a saving of $236. There are also other plans available. For specifications, and license info please click the link below. Get Intuit QuickBooks Desktop Pro Plus 2024 for just $299.99 This is a time limited deal For US customers only. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • AFAIK you shouldn't be getting a consent popup at all from Canada, so I think it is to do with a VPN or private/secure DNS.
    • From what I see it's only for Insider - preview builds. Not for everybody. So...
  • Recent Achievements

    • Week One Done
      agatameier earned a badge
      Week One Done
    • One Month Later
      agatameier earned a badge
      One Month Later
    • Week One Done
      ssd21345 earned a badge
      Week One Done
    • Contributor
      MarkHughes4096 went up a rank
      Contributor
    • Dedicated
      jordanspringer earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      175
    3. 3
      PsYcHoKiLLa
      139
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      76
  • Tell a friend

    Love Neowin? Tell a friend!