MS03-015 : Cumulative Patch for Internet Explorer


Recommended Posts

-----BEGIN PGP SIGNED MESSAGE-----

- -------------------------------------------------------------------

Title: Cumulative Patch for Internet Explorer (813489)

Date: 23 April 2003

Software: Microsoft © Internet Explorer

Impact: Run code of the attacker's choice on a user's machine.

Max Risk: Critical

Bulletin: MS03-015

Microsoft encourages customers to review the Security Bulletins at:

http://www.microsoft.com/technet/security/...in/MS03-015.asp

http://www.microsoft.com/security/security...ns/ms03-015.asp

- -------------------------------------------------------------------

Issue:

======

This is a cumulative patch that includes the functionality of all

previously released patches for Internet Explorer 5.01, 5.5 and

6.0. In addition, it eliminates the following four newly discovered

vulnerabilities:

- -A buffer overrun vulnerability in URLMON.DLL that occurs because

Internet Explorer does not correctly check the parameters of

information being received from a web server. It could be possible

for an attacker to exploit this vulnerability to run arbitrary code

on a user's system. A user simply visiting an attacker's website

could allow the attacker to exploit the vulnerability without any

other user action.

- -A vulnerability in the Internet Explorer file upload control that

allows input from a script to be passed to the upload control. This

vulnerability could allow an attacker to supply a file name to the

file upload control and automatically upload a file from the user's

system to a web server.

- -A flaw in the way Internet Explorer handles the rendering of third

party files. The vulnerability results because the Internet

Explorer method for rendering third party file types does not

properly check parameters passed to it. An attacker could create a

specially formed URL that would inject script during the rendering

of a third party file format and cause the script to execute in the

security context of the user.

- -A flaw in the way modal dialogs are treated by Internet Explorer

that occurs because an input parameter is not properly checked.

This flaw could allow an attacker to use an injected script to

provide access to files stored on a user's computer. Although a

user who visited the attacker's website could allow the attacker to

exploit the vulnerability without any other user action, an

attacker would have no way to force the user to visit the website.

In addition to eliminating the above vulnerabilities, this patch

also includes a fix for Internet Explorer 6.0 SP1 that corrects the

method by which Internet Explorer displays help information in the

local computer zone. While we are not aware of a method to exploit

this vulnerability by itself, if it were possible to exploit it, it

could allow an attacker to read local files on a visiting user's

system.

This patch also sets the Kill Bit on the Plugin.ocx ActiveX control

which has a security vulnerability. This killbit has been set in

order to ensure that the vulnerable control cannot be reintroduced

onto users' systems and to ensure that users who already have the

vulnerable control on their system are protected. This issue is

discussed further in Microsoft Knowledge Base Article 813489.

Like the previous Internet Explorer cumulative patch released with

bulletin MS03-004, this cumulative patch will cause

window.showHelp( ) to cease to function if you have not applied the

HTML Help update. If you have installed the updated HTML Help

control from Knowledge Base article 811830, you will still be able

to use HTML Help functionality after applying this patch.

Mitigating factors:

====================

There are common mitigating factors across all of the

vulnerabilities:

- -The attacker would have to host a web site that contained a web

page used to exploit the particular vulnerability.

- -By default, Outlook Express 6.0 and Outlook 2002 open HTML mails

in the Restricted Sites Zone. In addition, Outlook 98 and 2000 open

HTML mails in the Restricted Sites Zone if the Outlook Email

Security Update has been installed. Customers who use any of these

products would be at no risk from an e-mail borne attack that

attempted to automatically exploit these vulnerabilities. The

attacker would have no way to force users to visit a malicious web

site. Instead, the attacker would need to lure them there,

typically by getting them to click on a link that would take them

to the attacker's site.

In addition to the common factors, there are a number of individual

mitigating factors:

URLMON.DLL Buffer Overrun:

- -Code that executed on the system would only run under the

privileges of the locally logged in user.

File Upload Control vulnerability:

- -The attacker would have to know the explicit path and name of the

file to be uploaded in advance.

Third Party plug-in rendering:

- -The third party plugin would have to be present on the user's

system in order for it to be exploited

Risk Rating:

============

- Critical

Patch Availability:

===================

- A patch is available to fix this vulnerability. Please read the

Security Bulletins at

http://www.microsoft.com/technet/security/...in/ms03-015.asp

http://www.microsoft.com/security/security...ns/ms03-015.asp

for information on obtaining this patch.

- ----------------------------------------------------------------

Edited by xStainDx
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • DiskGenius 6.2.0.1829 - All Versions: Free, Lite & Portable by Razvan Serea DiskGenius is a full-featured partition manager, which is designed to optimize disk usage for Windows users. It will efficiently help you recover lost data, resize/split partition, backup files, edit hex data, check bad sectors, manage virtual disks, erase data, etc.. Create a system image backup for current Windows with simple clicks to keep the operating system under protection. DiskGenius key features: Partition Management - It can create format, resize, extend, backup, split, hide and clone partition, both MBR and GPT are supported. Disk and partition conversion - Convert dynamic disk to basic, convert virtual disk format and convert MBR to GPT, convert primary partition to logical. File recovery - It can recover files deleted or emptied form recycle bin, recover files from damaged partition or disk and recover files by file type and supports file preview and file filter. Partition recovery - It is the best partition recovery program in that it can recover files from damaged, corrupted and RAW partitions, search for lost partition and recover files from it, besides, it can fix partition table. RAID recovery - It can reconstruct Virtual RAID and recover files from it, and all RAID types are supported. Sector Editor - A Hex editor is embedded to help users edit raw hex data and recover data manually. Backup and Restore - It can backup and restore partition including system partition, hard disk and partition table. Bad Tracks - It can check and repair bad sectors for all storage devices; check hard disk S.M.A.R.T. information. Delete files permanently - It can delete files permanently so that they can't be recovered by any data recovery software. Virtual Disk - It supports virtual disks, including VMware, Virtual PC and Virtual Box. Create WinPE bootable disk and you can manage disk partition when system crashes or there is no operating system on your computer. Support FAT12/FAT16/FAt32/exFAT/NTFS/EXT2/EXT3/EXT4 file system format. DiskGenius 6.2.0.1829 changelog: Add the "Disk Speed Test" feature. Add the "Windows Boot Repair and Conversion" feature. Add the BMB21-2019 erase standard to the "Erase Sectors" feature. Add support for restoring an individual partition from a PMFX disk image file. Enhanced The "Verify Or Repair Bad Sectors/Blocks" feature displays disk read speed in the detection window during scanning. The "Quick Partition" dialog box allows users to quickly select the number of partitions by pressing the numeric keys 1, 2, 7, 8, or 9. The "Set Volume Name" dialog box supports selecting preset volume labels provided by the software. The "Copy Sectors" feature supports resuming copy tasks after modifying the number of skipped bad sectors. Add the "TRIM Optimization" option to the format dialog box. The "Clone Partition" and "Clone Disk" features perform TRIM optimization on target partitions or disks before cloning. Add support for Not Equal To search conditions (prefixed with "!") when searching hexadecimal data in the sector editor. Optimize the display of capacity values in the program interface to show two decimal places. Add a minimize button to dialogs that may require long processing time. Enhance support for the ReFS file system. Enhance support for newer HIF and MP4 formats when recovering files by type. Enhance support for the EXT4 file system. Enhance compatibility of the "File Recovery" feature with special data structures. Fixed Fixed the issue that the selected file system type automatically reverted to NTFS after changing it to exFAT or EXT4 in the "Quick Partition" dialog box. Fixed inaccurate Unicode string search results in the "Sector Editor" feature. Fixed the issue that exceptions might occur when adding multiple disks in the "Erase Sectors" feature. Fixed the issue that insufficient target disk space was incorrectly reported in some cases when cloning, backing up, or restoring disks. Fixed the issue that folder modification timestamps were not preserved when copying files from ReFS partitions. Fixed the issue that Excel-format reports generated by features such as file copying or bad sector checking could not be opened when the report contained more than one million rows. Fixed the issue that folders were not displayed in the exclude-folder dialog box when backing up partitions to image files. Fixed the issue that the "Erase Sectors" feature could not be executed in some cases. Download: DiskGenius 6.2.0.1829 | 63.9 MB (Freeware, paid upgrade available) Download: DiskGenius Portable 64-bit | 40.0 MB Download: DiskGenius Portable 32-bit | 36.0 MB Download: DiskGenius Lite 64-bit | 13.4 MB Download: DiskGenius Lite 32-bit | 11.6 MB View: DiskGenius Home Page | DiskGenius Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Really? Use a better search engine https://www.google.com/search?...ourceid=chrome&ie=UTF-8
    • Seems like Neowin has transitioned into being simps for the white house. I can't find a review for the last UFC games that came out.
  • Recent Achievements

    • Week One Done
      agatameier earned a badge
      Week One Done
    • One Month Later
      agatameier earned a badge
      One Month Later
    • Week One Done
      ssd21345 earned a badge
      Week One Done
    • Contributor
      MarkHughes4096 went up a rank
      Contributor
    • Dedicated
      jordanspringer earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      513
    2. 2
      +Edouard
      182
    3. 3
      PsYcHoKiLLa
      143
    4. 4
      ATLien_0
      95
    5. 5
      Steven P.
      75
  • Tell a friend

    Love Neowin? Tell a friend!