KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

Internet Explorer 7 Is an Open Door for Attacks


section: microsoft, for your questions: KezNews forum, 15.10.2007

Internet Explorer 7 on Windows XP and Windows Server 2003 is nothing short of an open door for attacks. Microsoft informed that it is currently investigating a remote code execution vulnerability in various versions of XP and Windows Server 2003 running Internet Explorer 7.




The Redmond company added that Windows Vista users are safe, although the operating system comes with IE7 built in by default. Windows XP SP2, XP Professional x64 Edition, Professional x64 Edition SP2; Windows Server 2003 SP1 and SP2, Windows Server 2003 x64 Edition and SP2 and Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems are all vulnerable to the security flaw, provided they are running IE7. The vulnerability is related to the way the Windows operating system handles Uniform Resource Identifiers (URIs).

"When a user clicks a link to a URI, the application showing that link to users decides how it is supposed to be handled. For traditionally "safe" protocols like mailto: or http: applications often just verify the prefix and then choose to call into the Windows shell32 function ShellExecute() to handle it. This has been the case for a number of years. Windows then launches Internet Explorer passing the URI or launches the preferred email client passing the email address etc. With IE6 installed, ShellExecute() passes the URI to IE which accepts it and inside IE determines it to be invalid. Navigation then fails harmlessly. With Internet Explorer 7 installed, the flow is a bit different", explained Jonathan Ness with the SWI team at Microsoft Security Response Center.

With IE7, Microsoft has implemented additional validation in the process of rejecting a malformed URI. Essentially, malformed URIs will no longer be rejected up front, and instead would be moved to ShellExecute() in order to be fixed. When ShellExecute() is handling URIs in order to make them usable, the process is not safely managed. In Vista, for example, ShellExecute() also rejects the URI, but the copies of Windows XP and Windows Server 2003 do not deliver a similar behavior. Microsoft emphasized that the vulnerability can be successfully exploited only in the limited contexts described above, and that other versions of the Windows operating system with IE7 installed are not affected.

"Our plan is to revise our URI handling code within ShellExecute() to be more strict. While our update will help protect all applications from malformed URI’s, application vendors who handle URI’s can also do stricter validation themselves to prevent malicious URI’s from being passed to ShellExecute(). We have seen several vendors introduce additional validation as a way to protect their customers from this issue", Ness added.

source: news.softpedia.com

send email Send link 2 friend  |  Permalink
<< previouse article
Microsoft Denies Changing Windows Vista Settings without Users' Consent
next article >>
The mystery continues: Why are Windows machines automatically updating themselves?

MORE RELATED ARTICLES:
Internet Explorer 8, to Be or Not to Be || Internet Explorer 8? 2008? 2009? || Original Internet Explorer 7 without WGA! || Internet Explorer 7 Readiness Toolkit || 49 Versions of Internet Explorer from IE 1.0 to IE 7.0

Comments(9)

IE6 Safer than IE7

By URL Me on 15.10.2007 - 22:10
improved security? go back to ie6 and your safer from this type of attack, tan using ie7 which was suppose to be more about security...

url attacks now? how can it become any easier than just with an url?

http:://attackunow.ms is all it takes!

Hate IE7

By HATE on 16.10.2007 - 14:10
i really hate that damn browser. i have vista 32 bit ultimate and ie7 and to say it is the worst browser version i have ever seen. keep freezing or crashing. i removed any plug in and still doing the same. hate hate hate it!!!
but love firefox!

firefox is so much better

By jimmy on 16.10.2007 - 16:10
firefox should be standard, much better than ie7

ChineseMan posted twice

By jimmy on 16.10.2007 - 21:10
firefox is clearly better, people like chineseman are just too dumb to try it or to use it for that matter.

firefox, real alternative

By swandike on 16.10.2007 - 21:10
firefox, no validation, fast, recovery from accidental shutdown, what else. ms should let firefox into its world.

ie 7 is a bit nice tho i must confess. just disable phising and dont add google toolbars and all others

IE7pro

By best plugin on 16.10.2007 - 23:10
if you want ff in ie7 use the plug in ie7pro....

great ad blocking and filter as well as spell checker, tab recovery and history.

firefox, real alternative

By swandike on 17.10.2007 - 20:10
if u want ff in ie7 use the plugin ie7pro...well ff has more than spell check, tab recovery and history.

check out ff list of plugins and addons and themes etc....uncountable. ie7 can subtitute ff...peace.

firefox, real alternative

By swandike on 17.10.2007 - 20:10
ffs what did i type up there? just dont give ms any chance to monopolise the world. we all like diverse choices.

ie 6 safer than ie 7

By nick on 18.10.2007 - 09:10
if i go back to ie 6 will i now have malformed url weakness? and why am i getting not valid comment message?


No new comments are allowed for this article.

For your questions use our KezNews Forum