ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Explorer flaw creates 'critical' worm-hole

Patrick Gray and Robert Lemos, CNET News.com CNET News.com

Published: 26 Jun 2003 09:07 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A vulnerability in Microsoft's Internet Explorer could result in the creation of a serious Internet worm, security experts have warned.

Although there is no proof that the vulnerability foretells the execution of arbitrary code, which would allow an attacker or worm to take control of a person's system, there's a strong possibility that the vulnerability is critical.

Freelance security consultant Dave Matthews says that if the bug is fully exploitable, then someone has undoubtedly figured it out by now.

"It's reasonably dangerous. It will require an effective payload to turn it into something more useful. Presumably, someone out there has something already," he told ZDNet Australia.

The potentially critical security flaw was disclosed to the Bugtraq security mailing list, in an act that Matthews says was most likely intended to antagonise the software giant. The buffer-overflow vulnerability is triggered by a malicious Java script that can be embedded in an HTML document. When a Web page or HTML file containing the malicious script is viewed by Internet Explorer, versions 5 and 6, the buffer is overrun and the browser crashes.

The code was posted to the BugTraq security mailing list early Sunday morning, but didn't garner much attention until Kevin Finisterre, a security researcher with consultancy Secure Network Operations, confirmed that it crashed IE 6.

"A bug like this could be triggered via a number of means...through email, simply browsing a web page, perhaps browsing a network share," he wrote in an email to CNET News.com. He warned that a worm could be a possibility, but stressed that the flaw only crashes Internet Explorer; no one has yet found a way to use the flaw to force IE to run code. Vulnerabilities that crash applications frequently suggest the possibility of a bigger problem, but Finisterre said other conditions could make exploiting the hole harder.

"It appears to be a little more difficult than your vanilla buffer overflow because all of the data supplied by the attacker is converted to uppercase," he said. That means that the code sent by an attacker to run on the targeted machine would have to work in all capital letters.

A Microsoft representative said that the company is investigating the issue and wouldn't speculate on how dangerous the flaw might be. The software maker wasn't pleased with the premature revelation of the vulnerability before its security teams got a chance to look into the matter. "Its publication may put our customers at risk or at the very least cause customers needless confusion and apprehension," the representative wrote to News.com.

Jamie Gillespie, a security analyst with AusCERT, a clearinghouse for vulnerability information, says it may be too early to go on full alert.

"It is a possibility that it could execute arbitrary code. That has not been proven," he said. "It's hard to say without knowing the internal coding structure of IE."

He did, however, concede that the flaw could pose a risk.

"Most buffer overflows do have a strong possibility to allow the execution of arbitrary code," he said.

According to Gillespie, Microsoft is looking into the issue, but as yet a patch is unavailable. Antivirus scanners will be of little use until definitions are updated, and even then they will be of limited use. What is needed is a patch.

Because the general perception is that HTML is much safer than executable code, such as .exe, .pif and .scr files, chances are that messaging gateways will allow the code to slip into user in-boxes, according to Chy Chuawiwat, managing director of content-filtering company Clearswift Australia.

"Pretty much everybody" allows HTML to pass through company-filtering gateways, he said. Of those, only a small proportion analyse the structure of the HTML code.

"30 percent use some kind of a script analysis tool to look for malicious code in HTML, but if it's not a known pattern that looks malicious it won't pick it up," he said.

Clearswift and other content-filtering and antivirus companies are analyzing the bug to determine the best course of action.

ZDNet Australia's Patrick Gray reported from Sydney.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
43 out of 68 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

C++/Unix Developer-FI-London-75,000-C++/Unix

You will use your skills in C++, UNIX, multithreading, Boost and Java script in order to build and support these complex-trading applications. My ...

SOP Author

Quality Review and Approval of SOP's / Operational Documents *Assist and Advise the SAP project on Validation aspect of the project including: ...

Manual Tester East London

The group are looking for enthusiastic people to start straight away, carrying out test script creation/execution, defect identification and metrics ...

Discussions

David Long David Long

Defragging: Merits?

Thursday 24 July 2008, 10:30 AM

12 posts

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal