[underpop] CAIS-Alerta: Patch acumulativo para MS Internet Explorer (MS04-025)
Brought to you by:
mikhail
|
From: <und...@li...> - 2004-08-02 14:01:09
|
CAIS-Alerta: Patch acumulativo para MS Internet Explorer (MS04-025)=20
=20=20=20=20=20
=20=20=20=20=20
Prezados,
O CAIS esta' repassando o alerta da Microsoft, intitulado "Microsoft=
=20
Security Bulletin MS04-025 - Cumulative Security Update for Internet=
=20
Explorer (867801)". Este alerta trata da disponibilizacao de um patch=
=20
acumulativo para o Microsoft Internet Explorer e elimina vulnerabilid=
ades=20
que, se exploradas, permitem que um atacante obtenha controle total s=
ob um=20
sistema afetado, podendo instalar programas ou adicionar novas contas=
com=20
privilegios administrativos, por exemplo.
Este patch e' classificado como critico e substitui aquele tratado em=
=20
MS04-004.
Correcoes disponiveis:
. Internet Explorer 5.01 Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyId=3D507E71EF=
-076B-43C4-8028-E91FCFAB252B&displaylang=3Den
. Internet Explorer 5.01 Service Pack 3
http://www.microsoft.com/downloads/details.aspx?FamilyId=3D7AA6F31D=
-7350-43F8-B72E-ED9D62577A60&displaylang=3Den
. Internet Explorer 5.01 Service Pack 4
http://www.microsoft.com/downloads/details.aspx?FamilyId=3D862E6914=
-821A-4C51-985B-C3958FAD3D4C&displaylang=3Den
. Internet Explorer 5.5 Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyId=3DE458480C=
-93F6-454A-A663-FC187C18CD9B&displaylang=3Den
. Internet Explorer 6
http://www.microsoft.com/downloads/details.aspx?FamilyId=3D4C2F8A40=
-1B88-4F93-98B1-1619DCFD7273&displaylang=3Den
. Internet Explorer 6 Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=3D06F49985=
-F19F-4B50-A75F-7636D8BEE576&displaylang=3Den
. Internet Explorer 6 Service Pack 1 (64-Bit Edition)
http://www.microsoft.com/downloads/details.aspx?FamilyId=3DFCDA580D=
-9E3B-4B44-BD65-C8D37A0DD62D&displaylang=3Den
. Internet Explorer 6 para Windows Server 2003
http://www.microsoft.com/downloads/details.aspx?FamilyId=3DD86262D9=
-C66A-4608-8DBE-2492B4AFBC3B&displaylang=3Den
. Internet Explorer 6 para Windows Server 2003 (64-Bit Edition)
http://www.microsoft.com/downloads/details.aspx?FamilyId=3D1AA8F5A9=
-71D3-48F7-BB32-F8A4D36C5FB9&displaylang=3Den
Mais informacoes:
. Microsoft Security Bulletin MS04-025
Cumulative Security Update for Internet Explorer (867801)
http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx
. Microsoft Security Bulletin MS04-004
Cumulative Security Update for Internet Explorer (832894)
http://www.microsoft.com/technet/security/bulletin/ms04-004.mspx
. Microsoft Brasil Security
http://www.microsoft.com/brasil/security
. Technet Brasil - Central de Seguranca
http://www.technetbrasil.com.br/seguranca
Identificadores CVE (http://cve.mitre.org): CAN-2004-0549, CAN-2004-0=
566 e=20
CAN-2003-1048
O CAIS recomenda que os administradores mantenham seus sistemas e apl=
icativos
sempre atualizados, de acordo com as ultimas versoes e correcoes
oferecidas pelos fabricantes.
Os Alertas do CAIS tambem sao oferecidos no formato RSS/RDF:
http://www.rnp.br/cais/alertas/rss.xml
Atenciosamente,
################################################################
# CENTRO DE ATENDIMENTO A INCIDENTES DE SEGURANCA (CAIS) #
# Rede Nacional de Ensino e Pesquisa (RNP) #
# #
# ca...@ca... http://www.cais.rnp.br #
# Tel. 019-37873300 Fax. 019-37873301 #
# Chave PGP disponivel http://www.rnp.br/cais/cais-pgp.key #
################################################################
Microsoft Security Bulletin MS04-025
Cumulative Security Update for Internet Explorer (867801)
Issued: July 30, 2004
Version: 1.0
Summary
Who should read this document: Customers who use Microsoft Internet=20
Explorer
Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Recommendation: Customers should apply the update immediately.
Security Update Replacement: This update replaces the one that is pro=
vided=20
in Microsoft Security Bulletin MS04-004, which is itself a cumulative=
=20
update.
Caveats: This update does not include hotfixes for Internet Explorer=
=20
provided since the release of MS04-004. Customers who have received=20
hotfixes from Microsoft or their support providers since the release =
of=20
MS04-004 should review the FAQ section for this update to determine h=
ow=20
this update might impact their operating systems.
Tested Software and Security Update Download Locations:
Affected Software:
Microsoft Windows NT Workstation 4.0 Service Pack 6a
Microsoft Windows NT Server 4.0 Service Pack 6a
Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack =
6
Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service=
Pack=20
3, Microsoft Windows 2000 Service Pack 4
Microsoft Windows XP and Microsoft Windows XP Service Pack 1
Microsoft Windows XP 64-Bit Edition Service Pack 1
Microsoft Windows XP 64-Bit Edition Version 2003
Microsoft Windows Server 2003
Microsoft Windows Server 2003 64-Bit Edition
Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and=20
Microsoft Windows Millennium Edition (Me) Review the FAQ section of =
this=20
bulletin for details about these operating systems.
Tested Microsoft Windows Components:
Affected Components:
Internet Explorer 5.01 Service Pack 2: Download the update.
Internet Explorer 5.01 Service Pack 3: Download the update.
Internet Explorer 5.01 Service Pack 4: Download the update.
Internet Explorer 5.5 Service Pack 2: Download the update.
Internet Explorer 6: Download the update.
Internet Explorer 6 Service Pack 1: Download the update.
Internet Explorer 6 Service Pack 1 (64-Bit Edition): Download the upd=
ate.
Internet Explorer 6 for Windows Server 2003: Download the update.
Internet Explorer 6 for Windows Server 2003 (64-Bit Edition): Downloa=
d the=20
update.
The software in this list has been tested to determine if the version=
s are=20
affected. Other versions either no longer include security update sup=
port=20
or may not be affected. To determine the support lifecycle for your=20
product and version, visit the following Microsoft Support Lifecycle =
Web=20
site.
Top of section
General Information
Executive Summary
Executive Summary:
This update resolves several newly discovered public vulnerabilities.=
Each=20
vulnerability is documented in this bulletin in its own Vulnerability=
=20
Details section.
If a user is logged on with administrative privileges, an attacker wh=
o=20
successfully exploited the most severe of these vulnerabilities could=
take=20
complete control of an affected system, including installing programs=
;=20
viewing, changing, or deleting data; or creating new accounts with fu=
ll=20
privileges. Users whose accounts are configured to have fewer privile=
ges=20
on the system would be at less risk than users who operate with=20
administrative privileges.
Microsoft recommends that customers apply the update immediately.
Severity Ratings and Vulnerability Identifiers:
Vulnerability Identifiers Impact of Vulnerability Internet Explorer=20
5.01 SP2, SP3, SP4 Internet Explorer 5.5 SP2 Internet Explorer=20
6 Internet Explorer 6 SP1 (All versions earlier than Windows Server=20
2003) Internet Explorer 6 for Windows Server 2003 (including 64-bit=20
Edition)
Navigation Method Cross-Domain Vulnerability - CAN-2004-0549
Remote Code Execution
None
Critical
Critical
Critical
Moderate
Malformed BMP File Buffer Overrun Vulnerability
CAN-2004-0566
Remote Code Execution
Critical
Critical
Critical
None
None
Malformed GIF File Double Free Vulnerability - CAN-2003-1048
Remote Code Execution
Critical
Critical
Critical
Critical
Critical
Aggregate Severity of All Vulnerabilities
=20=20=20=20=20=20=20
Critical
Critical
Critical
Critical
Critical
This assessment is based on the types of systems that are affected by=
the=20
vulnerability, their typical deployment patterns, and the effect that=
=20
exploiting the vulnerability would have on them.
Top of section
Frequently asked questions (FAQ) related to this security update
Why does this update address several reported security vulnerabilitie=
s?
This update contains support for several vulnerabilities because the=
=20
modifications that are required to address these issues are located i=
n=20
related files. Instead of having to install several updates that are=
=20
almost the same, customers can install only this update.
What updates does this release replace?
This is a cumulative update that includes the functionality of all th=
e=20
previously released updates for Internet Explorer. The security bulle=
tin=20
ID and operating systems that are affected for the previous Internet=
=20
Explorer update are listed in the following table.
Bulletin ID Internet Explorer 5.01 SP2, SP3, SP4 Internet Explorer=20
5.5 SP2 Internet Explorer 6 Internet Explorer 6 SP1 (All versions=20
earlier than Windows Server 2003) Internet Explorer 6 for Windows=20
Server 2003 (including 64-bit Edition)
MS04-004
Replaced
Replaced
Replaced
Replaced
Replaced
Ive received a hotfix from Microsoft or my support provider since the=
=20
release of MS04-004. Is that hotfix included in this Security Update?
No. For all operating systems besides Microsoft Windows Server 2003 o=
r=20
Microsoft Windows 64-Bit Edition Version 2003, most hotfixes created =
after=20
MS04-004 are not included in this security update. Installing this=20
security update will remove these hotfixes from the system. An update=
=20
rollup is available that contains these hotfixes as well as fixes for=
all=20
the security issues addressed in this update. For more information on=
what=20
hotfixes are not included in this security update but that are includ=
ed in=20
the update rollup, as well as instructions on how to obtain and deplo=
y the=20
update rollup, contact your Microsoft support provider or review Micr=
osoft=20
Knowledge Base Article 871260.
Ive installed a publicly available Update for Internet Explorer since=
the=20
release of MS04-004. Is this update included in this Security Update?
Yes, the publicly available updates for Internet Explorer released si=
nce=20
MS04-004 are included in this security update. This includes the foll=
owing=20
updates:
The update for Internet Explorer 6 Service Pack 1 provided with Micro=
soft=20
Knowledge Base Article 836117 entitled You cannot log on to a Web sit=
e or=20
complete an Internet transaction, or you receive an HTTP 500 (Interna=
l=20
Server Error) Web page
The update for Internet Explorer 5.5 Service Pack 2 provided with=20
Microsoft Knowledge Base Article 837209 entitled An HTTPS Web page do=
es=20
not download completely in Internet Explorer 5.5
The update for Internet Explorer 6 for Windows Server 2003 provided w=
ith=20
Microsoft Knowledge Base Article 839571 entitled Connections do not u=
se=20
LAN automatic configuration and proxy settings in Windows Server 2003
The update for Internet Explorer 6 for Windows Server 2003 provided w=
ith=20
Microsoft Knowledge Base Article 817786 entitled An Access Violation=
=20
Occurs When You Refresh a Web Page in Internet Explorer
Im running Windows XP Service Pack 1 and have received the hotfix=20
associated with Microsoft Knowledge Base Article 840309 from my Premi=
er=20
Support professional. What should I do before I apply this update?
Customers who have installed this hotfix may experience problems with=
=20
their desktop startup after installing this update. Microsoft Knowled=
ge=20
Base Article 840309 has been updated with workarounds to avoid these=
=20
symptoms.
Does this update contain any other security changes?
Yes. This update contains two additional security changes. The update=
=20
refines a change made in Internet Explorer 6 Service Pack 1, which=20
prevents web pages in the Internet zone from navigating to the Local=
=20
Machine zone. This change was introduced to mitigate the effects of=20
potential new cross domain vulnerabilities. The changes introduced in=
this=20
update are further enhancements of the Internet Explorer 6 Service Pa=
ck 1=20
restrictions. The update also further enforces the cross domain secur=
ity=20
model in Internet Explorer. This change is further documented in Micr=
osoft=20
Knowledge Base Article 875345
How does the extended support for Windows 98, Windows 98 Second Editi=
on,=20
and Windows Millennium Edition affect the release of security updates=
for=20
these operating systems?
Microsoft will only release security updates for critical security is=
sues.=20
Non-critical security issues are not offered during this support peri=
od.=20
For more information about the Microsoft Support Lifecycle policies f=
or=20
these operating systems, visit the following Web site.
For more information about severity ratings, visit the following Web =
site.
Note Critical security updates for these platforms may not be availab=
le=20
concurrently with the other security updates provided as part of this=
=20
security bulletin. They will be made available as soon as possible=20
following the release. When these security updates are available, you=
will=20
be able to download them only from the Windows Update Web site.
Are Windows 98, Windows 98 Second Edition, or Windows Millennium Edit=
ion=20
critically affected by any of the vulnerabilities that are addressed =
in=20
this security bulletin?
Yes. Windows 98, Windows 98 Second Edition, and Windows Millennium Ed=
ition=20
are critically affected by this vulnerability. Critical security upda=
tes=20
for these platforms may not be available concurrently with the other=
=20
security updates provided as part of this security bulletin. They wil=
l be=20
made available as soon as possible following the release. When these=
=20
security updates are available, you will be able to download them onl=
y=20
from the Windows Update Web site. For more information about severity=
=20
ratings, visit the following Web site.
I'm still using Microsoft Windows NT 4.0 Workstation Service Pack 6a =
or=20
Windows 2000 Service Pack 2, but extended security update support end=
ed on=20
June 30, 2004. However, this bulletin has a security update for these=
=20
operating system versions. Why is that?
Windows NT 4.0 Workstation Service Pack 6a and Windows 2000 Service P=
ack 2=20
have reached the end of their life cycles as previously documented, a=
nd=20
Microsoft extended this support to June 30, 2004. However, the end-of=
-life=20
for the extended support period occurred very recently. In this case,=
the=20
majority of the steps that are required to address this vulnerability=
were=20
completed before June 30, 2004. Therefore, we have decided to release=
=20
security updates for these operating system versions as part of this=
=20
security bulletin. We do not anticipate doing this for future=20
vulnerabilities affecting these operating system versions, but we res=
erve=20
the right to produce updates and to make these updates available when=
=20
necessary.
It should be a priority for customers who have these operating system=
=20
versions to migrate to supported versions to prevent potential exposu=
re to=20
future vulnerabilities. For more information about the Windows Produc=
t=20
Life Cycle, visit the following Microsoft Support Lifecycle Web site.=
For=20
more information about the extended security update support period fo=
r=20
these operating system versions, visit the following Microsoft Produc=
t=20
Support Services Web site.
Customers who require additional support for Windows NT Workstation 4=
.0=20
SP6a must contact their Microsoft account team representative, their=
=20
Technical Account Manager, or the appropriate Microsoft partner=20
representative for custom support options. Customers without an Allia=
nce,=20
Premier, or Authorized Contract can contact their local Microsoft sal=
es=20
office. For contact information, visit the Microsoft Worldwide Inform=
ation=20
Web site, select the country, and then click Go to see a list of phon=
e=20
numbers. When you call, ask to speak with the local Premier Support s=
ales=20
manager.
For more information, see the Windows Operating System FAQ.
Can I use the Microsoft Baseline Security Analyzer (MBSA) to determin=
e if=20
this update is required?
Yes. MBSA will determine if this update is required. For more informa=
tion=20
about MBSA, visit the MBSA Web site.
Note After April 20, 2004, the Mssecure.xml file that is used by MBSA=
=20
1.1.1 and earlier versions is no longer being updated with new securi=
ty=20
bulletin data. Therefore, scans that are performed after that date wi=
th=20
MBSA 1.1.1 or earlier will be incomplete. All users should upgrade to=
MBSA=20
1.2 because it provides more accurate security update detection and=20
supports additional products. Users can download MBSA 1.2 from the MB=
SA=20
Web site. For more information about MBSA support, visit the followin=
g=20
Microsoft Baseline Security Analyzer 1.2 Q&A Web site.
Can I use Systems Management Server (SMS) to determine if this update=
is=20
required?
Yes. SMS can help detect and deploy this security update. For informa=
tion=20
about SMS, visit the SMS Web site.
Top of section
Vulnerability Details
Navigation Method Cross-Domain Vulnerability - CAN-2004-0549:
A remote code execution vulnerability exists in Internet Explorer bec=
ause=20
of the way that it handles navigation methods. An attacker could expl=
oit=20
the vulnerability by constructing a malicious web page that could=20
potentially allow remote code execution if a user visited a malicious=
Web=20
site. An attacker who successfully exploited this vulnerability could=
run=20
malicious script code in the Local Machine security zone in Internet=
=20
Explorer. If a user is logged on with administrative privileges, this=
=20
could allow the attacker to take complete control of an affected syst=
em.
Mitigating Factors for Navigation Method Cross-Domain Vulnerability -=
=20
CAN-2004-0549:
In a Web-based attack scenario, an attacker would have to host a Web =
site=20
that contains a Web page that is used to exploit this vulnerability. =
An=20
attacker would have no way to force users to visit a malicious Web si=
te.=20
Instead, an attacker would have to persuade them to visit the Web sit=
e,=20
typically by getting them to click a link that takes them to the=20
attacker's site.
An attacker who successfully exploited this vulnerability could gain =
the=20
same privileges as the user. Users whose accounts are configured to h=
ave=20
fewer privileges on the system would be at less risk than users who=20
operate with administrative privileges.
Customers who have installed both the update referenced in Microsoft=
=20
Security Bulletin MS04-024 and have installed the ADODB.Stream update=
that=20
is referenced in Knowledge Base Article 870669 will be at a reduced r=
isk=20
of this vulnerability resulting in remote code execution.
By default, Outlook Express 6, Outlook 2002, and Outlook 2003 open HT=
ML=20
e-mail messages in the Restricted sites zone. Additionally, Outlook 9=
8 and=20
Outlook 2000 open HTML e-mail messages in the Restricted sites zone i=
f the=20
Outlook E-mail Security Update has been installed. Outlook Express 5.=
5=20
Service Pack 2 opens HTML e-mail in the Restricted sites zone if Micr=
osoft=20
Security Bulletin MS04-018 has been installed. The Restricted sites z=
one=20
helps reduce attacks that could attempt to exploit this vulnerability=
.
The risk of attack from the HTML e-mail vector can be significantly=20
reduced if you meet all the following conditions:
Apply the update that is included with Microsoft Security Bulletin=20
MS03-040 or a later Cumulative Security Update for Internet Explorer.
Use Outlook Express 5.5 Service Pack 2 or later and have applied the=
=20
update that is included with Microsoft Security Bulletin MS04-018 or =
a=20
later Cumulative Security Update for Outlook Express.
Use Microsoft Outlook 98 and Outlook 2000 with the Microsoft Outlook=
=20
E-mail Security Update installed
Use Microsoft Outlook Express 6 or later or Microsoft Outlook 2000 Se=
rvice=20
Pack 2 or later in their default configuration.
By default, Internet Explorer on Windows Server 2003 runs in a restri=
cted=20
mode that is known as Enhanced Security Configuration that mitigates =
this=20
vulnerability. See the FAQ section for this vulnerability for more=20
information about Internet Explorer Enhanced Security Configuration.
The following products are not affected by this vulnerability.
Internet Explorer 5.01 Service Pack 4 is not affected by this=20
vulnerability.
Internet Explorer 5.01 Service Pack 3 is not affected by this=20
vulnerability.
Internet Explorer 5.01 Service Pack 2 is not affected by this=20
vulnerability.
Top of section
Workarounds for Navigation Method Cross-Domain Vulnerability -=20
CAN-2004-0549:
Microsoft has tested the following workarounds. While these workaroun=
ds=20
will not correct the underlying vulnerability, they help block known=
=20
attack vectors. When a workaround reduces functionality, it is identi=
fied=20
below.
Set Internet and Local Intranet security zone settings to High to pro=
mpt=20
before running ActiveX control and Active scripting in the Internet z=
one=20
and Local Intranet zone.
You can help protect against these vulnerabilities by changing your=20
settings for the Internet security zone to prompt before running Acti=
veX=20
controls and Active scripting. To do this, follow these steps:
1.
In Internet Explorer, click Internet Options on the Tools menu.
2.
Click the Security tab.
3.
Click Internet, and click Custom Level.
4.
Under Settings, in the ActiveX controls and plug-ins section, under R=
un=20
ActiveX controls and plug-ins, click Prompt.
5.
In the Scripting section, under Active Scripting, click Prompt, and t=
hen=20
click OK.
6.
Click Local intranet, and then click Custom Level.
7.
Under Settings, in the ActiveX controls and plug-ins section, under R=
un=20
ActiveX controls and plug-ins, click Prompt.
8.
In the Scripting section, under Active Scripting, click Prompt.
9.
Click OK two times to return to Internet Explorer.
Impact of Workaround: There are side effects to prompting before runn=
ing=20
ActiveX controls. Many Web sites that are on the Internet or on an=20
intranet use ActiveX to provide additional functionality. For example=
, an=20
online e-commerce site or banking site may use ActiveX controls to pr=
ovide=20
menus, ordering forms, or even account statements. Prompting before=20
running ActiveX controls is a global setting that affects all Interne=
t and=20
intranet sites. You will be prompted frequently when you enable this=
=20
workaround. For each prompt, if you feel you trust the site that you =
are=20
visiting, click Yesto run ActiveX controls. If you do not want to be=
=20
prompted for all these sites, use the "Restrict Web sites to only you=
r=20
trusted Web sites" workaround.
Restrict Web sites to only your trusted Web sites
After you set Internet Explorer to require a prompt before it runs Ac=
tiveX=20
controls and active scripting in the Internet zone and in the Local=20
Intranet zone, you can add sites that you trust to Internet Explorer'=
s=20
Trusted sites zone. This will allow you to continue to use trusted We=
b=20
sites exactly as you do today, while helping to protect you from this=
=20
attack on untrusted sites. Microsoft recommends that you only add sit=
es=20
that you trust to the Trusted sites zone.
To do this follow these steps:
1.
In Internet Explorer, click Tools, click Internet Options, and then c=
lick=20
the Security tab.
2.
In the Select a Web content zone to specify its current security sett=
ings=20
box, click Trusted Sites, and then click Sites.
3.
If you want to add sites that do not require an encrypted channel, cl=
ick=20
to clear the Require server verification (https:) for all sites in th=
is=20
zone check box.
4.
In the Add this Web site to the zone box, type the URL of a site that=
you=20
trust, and then click Add.
5.
Repeat these steps for each site that you want to add to the zone
6.
Click OK two times to accept the changes and return to Internet Explo=
rer.
Add any sites that you trust not to take malicious action on your=20
computer. One in particular that you may want to add is=20
"*.windowsupdate.microsoft.com" (without the quotes). This is the sit=
e=20
that will host the update, and it requires the use of an ActiveX cont=
rol=20
to install the update.
Strengthen the security settings for the Local Machine zone in Intern=
et=20
Explorer
Because this vulnerability permits an attacker to run HTML code in th=
e=20
Local Machine security zone, users can reduce the impact of this=20
vulnerability by restricting the default settings in this zone. For m=
ore=20
information about these settings, and for more information about the=
=20
potential impacts of changing these default settings, see Microsoft=20
Knowledge Base Article 833633.
Impact of Workaround: Microsoft recommends that customers consider th=
ese=20
changes to Internet Explorer security settings as a last resort only.=
If=20
you make these changes, you may lose some functionality for some Wind=
ows=20
programs and components. Before you make these changes in a productio=
n=20
environment, test the changes extensively to verify that mission-crit=
ical=20
programs continue to work correctly for all users.
Install Outlook E-mail Security Update if you are using Outlook 2000 =
SP1=20
or earlier.
By default, Outlook Express 6, Outlook 2002, and Outlook 2003 open HT=
ML=20
e-mail messages in the Restricted sites zone. Additionally, Outlook 9=
8 and=20
Outlook 2000 open HTML e-mail messages in the Restricted sites zone i=
f the=20
Outlook E-mail Security Update has been installed.
Customers who use any of these products could be at a reduced risk fr=
om an=20
e-mail-borne attack that tries to exploit this vulnerability unless t=
he=20
user clicks a malicious link in the e-mail message.
Install Microsoft Security Bulletin MS04-018 if you are using Outlook=
=20
Express 5.5 SP2.
Outlook Express 5.5 Service Pack 2 opens HTML e-mail in the Restricte=
d=20
sites zone if Microsoft Security Bulletin MS04-018 has been installed=
.
Customers who use any of these products could be at a reduced risk fr=
om an=20
e-mail-borne attack that tries to exploit this vulnerability unless t=
he=20
user clicks a malicious link in the e-mail message.
Read e-mail messages in plain text format if you are using Outlook 20=
02 or=20
later, or Outlook Express 6 SP1 or later, to help protect yourself fr=
om=20
the HTML e-mail attack vector.
Microsoft Outlook 2002 users who have applied Office XP Service Pack =
1 or=20
later and Microsoft Outlook Express 6 users who have applied Internet=
=20
Explorer 6 Service Pack 1 can enable this setting and view e-mail mes=
sages=20
that are not digitally signed or e-mail messages that are not encrypt=
ed in=20
plain text only.
Digitally signed e-mail messages or encrypted e-mail messages are not=
=20
affected by the setting and may be read in their original formats. Fo=
r=20
more information about enabling this setting in Outlook 2002, see=20
Microsoft Knowledge Base Article 307594.
For information about this setting in Outlook Express 6, see Microsof=
t=20
Knowledge Base Article 291387.
Impact of Workaround: E-mail messages that are viewed in plain text f=
ormat=20
will not contain pictures, specialized fonts, animations, or other ri=
ch=20
content. In addition:
The changes are applied to the preview pane and to open messages.
Pictures become attachments so that they are not lost.
Because the message is still in Rich Text or HTML format in the store=
, the=20
object model (custom code solutions) may behave unexpectedly.
Top of section
FAQ for Navigation Method Cross-Domain Vulnerability - CAN-2004-0549:
What is the scope of the vulnerability?
This is a remote code execution vulnerability. If a user is logged on=
with=20
administrative privileges, an attacker who successfully exploited thi=
s=20
vulnerability could take complete control of an affected system. An=20
attacker could then install programs, view, change, or delete data; o=
r=20
create new accounts with full privileges. Users whose accounts are=20
configured to have fewer privileges on the system would be at less ri=
sk=20
than users who operate with administrative privileges.
What causes the vulnerability?
The process by which Navigation Methods are validated by the Internet=
=20
Explorer cross-domain security model.
What is the cross domain security model that Internet Explorer implem=
ents?
One of the principal security functions of a browser is to make sure =
that=20
browser windows that are under the control of different Web sites can=
not=20
interfere with each other or access each other's data, while allowing=
=20
windows from the same site to interact with each other. To differenti=
ate=20
between cooperative and uncooperative browser windows, the concept of=
a=20
"domain" has been created. A domain is a security boundary - any open=
=20
windows within the same domain can interact with each other, but wind=
ows=20
from different domains cannot. The cross-domain security model is the=
part=20
of the security architecture that keeps windows from different domain=
s=20
from interfering with each other.
The simplest example of a domain is associated with Web sites. If you=
=20
visit http://www.wingtiptoys.com, and it opens a window to=20
http://www.wingtiptoys.com/security, the two windows can interact wit=
h=20
each other because both sites belong to the same domain,=20
http://www.wingtiptoys.com. However, if you visited=20
http://www.wingtiptoys.com, and it opened a window to a different Web=
=20
site, the cross-domain security model would protect the two windows f=
rom=20
each other. The concept goes even further. The file system on your lo=
cal=20
computer is also a domain. For example, http://www.wingtiptoys.com co=
uld=20
open a window and show you a file on your hard disk. However, because=
your=20
local file system is in a different domain from the Web site, the=20
cross-domain security model should prevent the Web site from reading =
the=20
file that is being displayed.
The Internet Explorer cross-domain security model can be configured b=
y=20
using the security zone settings in Internet Explorer.
What are Internet Explorer security zones?
Internet Explorer security zones are part of a system that divides on=
line=20
content into categories or zones that are based on the trustworthines=
s of=20
the content. Specific Web domains can be assigned to a zone, dependin=
g on=20
how much trust is placed in the content of each domain. The zone then=
=20
restricts the capabilities of the Web content, based on the zone's po=
licy.=20
By default, most Internet domains are treated as part of the Internet=
=20
zone. By default, the policy of the Internet zone prevents scripts an=
d=20
other active code from accessing resources on the local system.
What might an attacker use the vulnerability to do?
An attacker who successfully exploited this vulnerability could run=20
malicious script code in the Local Machine security zone in Internet=
=20
Explorer. This could allow an attacker to take complete control of th=
e=20
affected system.
How could an attacker exploit the vulnerability?
An attacker could exploit this vulnerability by creating a malicious =
Web=20
page or an HTML e-mail message and then enticing the user to visit th=
is=20
page or to view the HTML e-mail message. When the user visited the pa=
ge or=20
viewed the e-mail message, the attacker could access information from=
=20
other websites, local files on the system, or cause script to run in =
the=20
security context of the Local Machine Zone.
What systems are primarily at risk from the vulnerability?
This vulnerability requires a user to be logged on and to be reading=
=20
e-mail or visiting Web sites for any malicious action to occur. There=
fore,=20
any systems where e-mail is read or where Internet Explorer is used=20
frequently, such as users workstations or terminal servers, are at th=
e=20
most risk from this vulnerability. Systems that are not typically use=
d to=20
read e-mail or to visit Web sites, such as most server systems, are a=
t a=20
reduced risk.
Are Windows 98, Windows 98 Second Edition or Windows Millennium Editi=
on=20
critically affected by this vulnerability?
Yes. Windows 98, Windows 98 Second Edition, and Windows Millennium Ed=
ition=20
are critically affected by this vulnerability. Critical security upda=
tes=20
for these platforms may not be available concurrently with the other=
=20
security updates provided as part of this security bulletin. They wil=
l be=20
made available as soon as possible following the release. When these=
=20
security updates are available, you will be able to download them onl=
y=20
from the Windows Update Web site. For more information about severity=
=20
ratings, visit the following Web site.
I am running Internet Explorer on Windows Server 2003. Does this miti=
gate=20
this vulnerability?
Yes. By default, Internet Explorer on Windows Server 2003 runs in a=20
restricted mode that is known as Enhanced Security Configuration that=
=20
mitigates this vulnerability.
What is Internet Explorer Enhanced Security Configuration?
Internet Explorer Enhanced Security Configuration is a group of=20
preconfigured Internet Explorer settings that reduce the likelihood o=
f a=20
user or of an administrator downloading and running malicious Web con=
tent=20
on a server. Internet Explorer Enhanced Security Configuration reduce=
s=20
this risk by modifying numerous security-related settings, including =
the=20
settings on the Security and the Advanced tab in the Internet Options=
=20
dialog box. Some of the important modifications include:
Security level for the Internet zone is set to High. This setting dis=
ables=20
scripts, ActiveX controls, Microsoft Java Virtual Machine (MSJVM), HT=
ML=20
content, and file downloads.
Automatic detection of intranet sites is disabled. This setting assig=
ns=20
all intranet Web sites and all Universal Naming Convention (UNC) path=
s=20
that are not explicitly listed in the Local intranet zone to the Inte=
rnet=20
zone.
Install On Demand and non-Microsoft browser extensions are disabled. =
This=20
setting prevents Web pages from automatically installing components a=
nd=20
prevents non-Microsoft extensions from running.
Multimedia content is disabled. This setting prevents music, animatio=
ns,=20
and video clips from running.
Could the vulnerability be exploited over the Internet?
Yes. An attacker may be able to exploit this vulnerability over the=20
Internet. Microsoft has provided information on how you can help prot=
ect=20
your PC. End users can visit the Protect Your PC Web site. IT=20
Professionals can visit the Security Guidance Center Web site.
What does the update do?
The update removes the vulnerability by modifying the way that Intern=
et=20
Explorer validates Navigation Methods.
When this security bulletin was issued, had this vulnerability been=20
publicly disclosed?
Yes. This vulnerability has been publicly disclosed. It has been assi=
gned=20
Common Vulnerability and Exposure number CAN-2004-0549. It also has b=
een=20
named 180 Solutions or Modal Dialog Vulnerability by the larger secur=
ity=20
community.
When this security bulletin was issued, had Microsoft received any re=
ports=20
that this vulnerability was being exploited?
Yes. When the security bulletin was released, Microsoft had received=
=20
information that this vulnerability was being exploited.
Does applying this security update help protect customers from the co=
de=20
that has been published publicly that attempts to exploit this=20
vulnerability?
Yes. This security update addresses the vulnerability that is current=
ly=20
being exploited. The vulnerability that has been addressed has been=20
assigned the Common Vulnerability and Exposure number CAN-2004-0549.
Top of section
Top of section
Malformed BMP File Buffer Overrun Vulnerability - CAN-2004-0566:
A buffer overrun vulnerability exists in the processing of BMP image =
file=20
formats that could allow remote code execution on an affected system.=
If=20
the user is logged on with administrative privileges an attacker who=
=20
successfully exploited this vulnerability could take complete control=
of=20
the affected system. Users whose accounts are configured to have fewe=
r=20
privileges on the system would be at less risk than users who operate=
with=20
administrative privileges.
Mitigating Factors for Malformed BMP File Buffer Overrun Vulnerabilit=
y -=20
CAN-2004-0566:
In a Web-based attack scenario, an attacker would have to host a Web =
site=20
that contains a Web page that is used to exploit this vulnerability. =
An=20
attacker would have no way to force users to visit a malicious Web si=
te.=20
Instead, an attacker would have to persuade them to visit the Web sit=
e,=20
typically by getting them to click a link that takes them to the=20
attacker's site.
An attacker who successfully exploited this vulnerability could gain =
the=20
same privileges as the user. Users whose accounts are configured to h=
ave=20
fewer privileges on the system would be at less risk than users who=20
operate with administrative privileges.
The following products are not affected by this vulnerability.
Internet Explorer 6 Service Pack 1 is not affected by this vulnerabil=
ity.
Internet Explorer 6 Service Pack 1 (64-Bit Edition) is not affected b=
y=20
this vulnerability.
Internet Explorer 6 for Windows Server 2003 is not affected by this=20
vulnerability.
Internet Explorer 6 for Windows Server 2003 (64-Bit Edition) is not=20
affected by this vulnerability.
Top of section
Workarounds for Malformed BMP File Buffer Overrun Vulnerability -=20
CAN-2004-0566:
Microsoft has tested the following workarounds. While these workaroun=
ds=20
will not correct the underlying vulnerability, they help block known=
=20
attack vectors. When a workaround reduces functionality, it is identi=
fied=20
below.
Read e-mail messages in plain text format if you are using Outlook 20=
02 or=20
later, or Outlook Express 6 SP1 or later, to help protect yourself fr=
om=20
the HTML e-mail attack vector.
Microsoft Outlook 2002 users who have applied Office XP Service Pack =
1 or=20
later and Microsoft Outlook Express 6 users who have applied Internet=
=20
Explorer 6 Service Pack 1 can enable this setting and view e-mail mes=
sages=20
that are not digitally signed or e-mail messages that are not encrypt=
ed in=20
plain text only.
Digitally signed e-mail messages or encrypted e-mail messages are not=
=20
affected by the setting and may be read in their original formats. Fo=
r=20
more information about enabling this setting in Outlook 2002, see=20
Microsoft Knowledge Base Article 307594.
For information about this setting in Outlook Express 6, see Microsof=
t=20
Knowledge Base Article 291387.
Impact of Workaround: E-mail messages that are viewed in plain text f=
ormat=20
will not contain pictures, specialized fonts, animations, or other ri=
ch=20
content. In addition:
The changes are applied to the preview pane and to open messages.
Pictures become attachments so that they are not lost.
Because the message is still in Rich Text or HTML format in the store=
, the=20
object model (custom code solutions) may behave unexpectedly.
Top of section
FAQ for Malformed BMP File Buffer Overrun Vulnerability - CAN-2004-05=
66:
What is the scope of the vulnerability?
This is a buffer overrun vulnerability. If a user is logged on with=20
administrative privileges, an attacker who successfully exploited thi=
s=20
vulnerability could take complete control of an affected system. An=20
attacker could then install programs, view, change, or delete data, o=
r=20
creating new accounts with full privileges. Users whose accounts are=
=20
configured to have fewer privileges on the system would be at less ri=
sk=20
than users who operate with administrative privileges.
What might an attacker use the vulnerability to do?
An attacker who successfully exploited this vulnerability could take=
=20
complete control of the affected system.
How could an attacker exploit the vulnerability?
This vulnerability could be exploited in scenarios that use Internet=
=20
Explorers BMP rendering code to view the malicious file. Here are som=
e=20
examples:
An attacker could host a malicious Web site that is designed to explo=
it=20
this vulnerability and then persuade a user to view the Web site.
An attacker could also create an HTML e-mail message that has a speci=
ally=20
crafted image designed to exploit this vulnerability attached. An att=
ack=20
could then persuade the user to view or preview the HTML e-mail messa=
ge.
An attacker could add a specially crafted image to the local file sys=
tem=20
or onto a network share and then persuade the user to preview the=20
directory.
What systems are primarily at risk from the vulnerability?
This vulnerability requires a user to be logged on and to be reading=
=20
e-mail or visiting Web sites for any malicious action to occur. There=
fore,=20
any systems where e-mail is read or where Internet Explorer is used=20
frequently, such as users workstations or terminal servers, are at th=
e=20
most risk from this vulnerability. Systems that are not typically use=
d to=20
read e-mail or to visit Web sites, such as most server systems, are a=
t a=20
reduced risk.
Are Windows 98, Windows 98 Second Edition or Windows Millennium Editi=
on=20
critically affected by this vulnerability?
Yes. Windows 98, Windows 98 Second Edition, and Windows Millennium Ed=
ition=20
are critically affected by this vulnerability. Critical security upda=
tes=20
for these platforms may not be available concurrently with the other=
=20
security updates provided as part of this security bulletin. They wil=
l be=20
made available as soon as possible following the release. When these=
=20
security updates are available, you will be able to download them onl=
y=20
from the Windows Update Web site. For more information about severity=
=20
ratings, visit the following Web site.
Could the vulnerability be exploited over the Internet?
Yes. An attacker may be able to exploit this vulnerability over the=20
Internet. Microsoft has provided information on how you can help prot=
ect=20
your PC. End users can visit the Protect Your PC Web site. IT=20
Professionals can visit the Security Guidance Center Web site.
What does the update do?
The update removes the vulnerability by modifying the way that Intern=
et=20
Explorer validates BMP files when they are opened.
When this security bulletin was issued, had this vulnerability been=20
publicly disclosed?
Yes. This vulnerability has been publicly disclosed. It has been assi=
gned=20
Common Vulnerability and Exposure number CAN-2004-0566.
When this security bulletin was issued, had Microsoft received any re=
ports=20
that this vulnerability was being exploited?
Yes. When the security bulletin was released, Microsoft had received=
=20
information that this vulnerability was being exploited.
Does applying this security update help protect customers from the co=
de=20
that has been published publicly that attempts to exploit this=20
vulnerability?
Yes. This security update addresses the vulnerability that is current=
ly=20
being exploited. The vulnerability that has been addressed has been=20
assigned the Common Vulnerability and Exposure number CAN-2004-0566.
Top of section
Top of section
Malformed GIF File Double Free Vulnerability - CAN-2003-1048:
Abuffer overrun vulnerability exists in the processing of GIF image f=
ile=20
formats that could allow remote code execution on an affected system.=
If=20
the user is logged on with administrative privileges, an attacker who=
=20
successfully exploited this vulnerability could take complete control=
of=20
the affected system. Users whose accounts are configured to have fewe=
r=20
privileges on the system would be at less risk than users who operate=
with=20
administrative privileges.
Mitigating Factors for Malformed GIF File Double Free Vulnerability -=
=20
CAN-2003-1048:
In a Web-based attack scenario, an attacker would have to host a Web =
site=20
that contains a Web page that is used to exploit this vulnerability. =
An=20
attacker would have no way to force users to visit a malicious Web si=
te.=20
Instead, an attacker would have to persuade them to visit the Web sit=
e,=20
typically by getting them to click a link that takes them to the=20
attacker's site.
An attacker who successfully exploited this vulnerability could gain =
the=20
same privileges as the user. Users whose accounts are configured to h=
ave=20
fewer privileges on the system would be at less risk than users who=20
operate with administrative privileges.
Because of the unique layout of the memory structures on each affecte=
d=20
system, exploiting this vulnerability on a mass scale could potential=
ly be=20
difficult.
Top of section
Workarounds for Malformed GIF File Double Free Vulnerability -=20
CAN-2003-1048:
Microsoft has tested the following workarounds. While these workaroun=
ds=20
will not correct the underlying vulnerability, they help block known=
=20
attack vectors. When a workaround reduces functionality, it is identi=
fied=20
below.
Read e-mail messages in plain text format if you are using Outlook 20=
02 or=20
later, or Outlook Express 6 SP1 or later, to help protect yourself fr=
om=20
the HTML e-mail attack vector.
Microsoft Outlook 2002 users who have applied Office XP Service Pack =
1 or=20
later and Microsoft Outlook Express 6 users who have applied Internet=
=20
Explorer 6 Service Pack 1 can enable this setting and view e-mail mes=
sages=20
that are not digitally signed or e-mail messages that are not encrypt=
ed in=20
plain text only.
Digitally signed e-mail messages or encrypted e-mail messages are not=
=20
affected by the setting and may be read in their original formats. Fo=
r=20
more information about enabling this setting in Outlook 2002, see=20
Microsoft Knowledge Base Article 307594.
For information about this setting in Outlook Express 6, see Microsof=
t=20
Knowledge Base Article 291387.
Impact of Workaround: E-mail messages that are viewed in plain text f=
ormat=20
will not contain pictures, specialized fonts, animations, or other ri=
ch=20
content. In addition:
The changes are applied to the preview pane and to open messages.
Pictures become attachments so that they are not lost.
Because the message is still in Rich Text or HTML format in the store=
, the=20
object model (custom code solutions) may behave unexpectedly.
Top of section
FAQ for Malformed GIF File Double Free Vulnerability - CAN-2003-1048:
What is the scope of the vulnerability?
This is a denial of service vulnerability, but it is also potential r=
emote=20
code execution vulnerability. If the user is logged on with administr=
ative=20
privileges, an attacker who successfully exploited this vulnerability=
to=20
allow code execution could gain complete control over an affected sys=
tem=20
and could then install programs; view, change, or delete data, or cre=
ate=20
new accounts that have full privileges Users whose accounts are confi=
gured=20
to have fewer privileges on the system would be at less risk than use=
rs=20
who operate with administrative privileges.
What is a double free condition?
An attacker could cause an affected system, while processing a specia=
lly=20
crafted GIF file, to try to release or free memory that may have alre=
ady=20
been set aside for use. Releasing memory that has already been freed =
could=20
lead to memory corruption. An attacker could add arbitrary code to me=
mory=20
that is then executed when the corruption occurs. If the user is logg=
ed on=20
with administrative privileges, this code could then be executed at a=
=20
system level of privilege.
Typically, this vulnerability will cause a denial of service to occur=
.=20
However, on a limited basis, code execution could occur. Because of t=
he=20
unique layout of the memory on each affected system, exploiting this=
=20
vulnerability on a mass scale could potentially be difficult.
What might an attacker use the vulnerability to do?
An attacker who successfully exploited this vulnerability could take=
=20
complete control of the affected system.
How could an attacker exploit the vulnerability?
This vulnerability could be exploited in scenarios that use Internet=
=20
Explorers GIF rendering code to view the malicious file. Here are som=
e=20
examples:
An attacker could host a malicious Web site that is designed to explo=
it=20
this vulnerability and then persuade a user to view the Web site.
An attacker could also create an HTML e-mail message that has a speci=
ally=20
crafted image designed to exploit this vulnerability attached. An att=
ack=20
could then persuade the user to view or preview the HTML e-mail messa=
ge.
An attacker could add a specially crafted image to the local file sys=
tem=20
or onto a network share and then persuade the user to preview the=20
directory.
What systems are primarily at risk from the vulnerability?
This vulnerability requires a user to be logged on and to be reading=
=20
e-mail or visiting Web sites for any malicious action to occur. There=
fore,=20
any systems where e-mail is read or where Internet Explorer is used=20
frequently, such as users workstations or terminal servers, are at th=
e=20
most risk from this vulnerability. Systems that are not typically use=
d to=20
read e-mail or to visit Web sites, such as most server systems, are a=
t a=20
reduced risk.
Are Windows 98, Windows 98 Second Edition or Windows Millennium Editi=
on=20
critically affected by this vulnerability?
Yes. Windows 98, Windows 98 Second Edition, and Windows Millennium Ed=
ition=20
are critically affected by this vulnerability. Critical security upda=
tes=20
for these platforms may not be available concurrently with the other=
=20
security updates provided as part of this security bulletin. They wil=
l be=20
made available as soon as possible following the release. When these=
=20
security updates are available, you will be able to download them onl=
y=20
from the Windows Update Web site. For more information about severity=
=20
ratings, visit the following Web site.
Could the vulnerability be exploited over the Internet?
Yes. An attacker may be able to exploit this vulnerability over the=20
Internet. Microsoft has provided information on how you can help prot=
ect=20
your PC. End users can visit the Protect Your PC Web site. IT=20
Professionals can visit the Security Guidance Center Web site.
What does the update do?
The update removes the vulnerability by modifying the way that Intern=
et=20
Explorer validates GIF files when they are opened.
When this security bulletin was issued, had this vulnerability been=20
publicly disclosed?
Yes. This vulnerability has been publicly disclosed. It has been assi=
gned=20
Common Vulnerability and Exposure number CAN-2003-1048.
When this security bulletin was issued, had Microsoft received any re=
ports=20
that this vulnerability was being exploited?
No. Microsoft had seen examples of proof of concept code published=20
publicly but had not received any information indicating that this=20
vulnerability had been publicly used to attack customers when this=20
security bulletin was originally issued.
Top of section
Top of section
Top of section
Security Update Information
Installation Platforms and Prerequisites:
For additional information about how to determine which version of=20
Internet Explorer you are running, click the following article number=
to=20
view the article in the Microsoft Knowledge Base:
164539 How to Determine Which Version of Internet Explorer Is Install=
ed
For information about the specific security update for your platform,=
=20
click the appropriate link:
Internet Explorer 6 for Windows Server 2003 (all versions) and Window=
s XP=20
64-bit Edition, Version 2003
Prerequisites
This update requires Internet Explorer 6 (version 6.00.3790.0000) on=
=20
Windows Server 2003 (32-bit or 64-bit) or Internet Explorer 6 (versio=
n=20
6.00.3790.0000) on Windows XP 64-Bit Edition, Version 2003.
Inclusion in Future Service Packs:
The update for this issue will be included in Windows Server 2003 Ser=
vice=20
Pack 1.
Installation Information
This security update supports the following setup switches:
/help Displays the command line options
Setup Modes
/quiet Quiet mode (no user interaction or displa=
y)
/passive Unattended mode (progress bar only)
/uninstall Uninstalls the package
Restart Options
/norestart Do not restart when installation is complet=
e
/forcerestart Restart after installation
Special Options
/l Lists installed Windows hotfixes or u=
pdate=20
packages
/o Overwrite OEM files without prompting
/n Do not backup files needed for uninsta=
ll
/f Force other programs to close when th=
e=20
computer shuts down
/extract Extracts files without starting setup
Note You can combine these switches into one command. For backward=20
compatibility, the security update also supports the setup switches t=
hat=20
the previous version of the setup utility uses. For more information =
about=20
the supported installation switches, see Microsoft Knowledge Base Art=
icle=20
about the supported installation switches, see Microsoft Knowledge Ba=
se=20
Article 262841.
Deployment Information
To install the security update without any user intervention, use the=
=20
following command at a command prompt for Windows Server 2003:
Windowsserver2003-kb867801-x86-enu /passive /quiet
To install the security update without forcing the system to restart,=
use=20
the following command at a command prompt for Windows Server 2003:
Windowsserver2003-kb867801-x86-enu /norestart
For information about how to deploy this security update with Softwar=
e=20
Update Services, visit the Software Update Services Web site.
Restart Requirement
You must restart your system after you apply this security update. Yo=
u do=20
not have to use an administrator logon after the computer restarts fo=
r any=20
version of this update.
Removal Information
To remove this update, use the Add or Remove Programs tool in Control=
=20
Panel.
System administrators can also use the Spuninst.exe utility to remove=
this=20
security update. The Spuninst.exe utility is located in the=20
%Wi...
[truncated message content] |