O-002: Microsoft Internet Explorer Cumulative Patch Privacy and Legal Notice

CIAC INFORMATION BULLETIN

O-002: Microsoft Internet Explorer Cumulative Patch

[Microsoft Security Bulletin MS03-040]

October 6, 2003 14:00 GMT

PROBLEM: There are two new vulnerabilities in IE:
1) A vulnerability occurs because Internet Explorer does not properly determine an object type returned from a Web server in a popup window.
2) A vulnerability occurs because Internet Explorer does not properly determine an object type returned from a Web server during XML data binding.
PLATFORM: Microsoft Internet Explorer 5.01, 5.5, 6.0, 6.0 for Windows Server 2003
DAMAGE: It could be possible for an attacker who exploited this vulnerability to run arbitrary code on a user's system.
SOLUTION: Apply patch immediately. (NOTE--This patch supersedes the one provided in Microsoft Security Bulletin MS03-032 which is itself a cumulative patch.)

VULNERABILITY
ASSESSMENT:
The risk is HIGH. There are rumors that exploits are already in the wild. It is possible for an attacker to run arbitrary code.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/o-002.shtml
  ORIGINAL BULLETIN: http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-040.asp
  CVE: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=
CVE-2003-0838 CVE-2003-0809

[***** Start Microsoft Security Bulletin MS03-040 *****]

Microsoft Security Bulletin MS03-040    

Cumulative Patch for Internet Explorer (828750)
Originally posted: October 3, 2003

Summary

Who should read this bulletin: Users running Microsoft Internet Explorer. 

Impact of vulnerability: Run code of attacker’s choice. 

Maximum Severity Rating: Critical 

Recommendation: Customers should apply the patch immediately.

End User Bulletin:
An end user version of this bulletin is available at: 

http://www.microsoft.com/security/security_bulletins/ms03-040.asp 

Protect your PC:
Additional information on how you can help protect your PC is available at the following locations: 


Affected Software: 


Technical details

Technical description: 

This is a cumulative patch that includes the functionality of all previously released patches for 
Internet Explorer 5.01, 5.5 and 6.0. In addition, it eliminates the following newly discovered 
vulnerabilities:


In addition, a change has been made to the method by which Internet Explorer handles Dynamic HTML (DHTML) 
Behaviors in the Internet Explorer Restricted Zone. It could be possible for an attacker exploiting a 
separate vulnerability (such as one of the two vulnerabilities discussed above) to cause Internet Explorer 
to run script code in the security context of the Internet Zone. In addition, an attacker could use Windows 
Media Player’s (WMP) ability to open URLs to construct an attack. An attacker could also craft an HTML-
based e-mail that could attempt to exploit this behavior.

To exploit these flaws, the attacker would have to create a specially formed HTML–based e-mail and send 
it to the user. Alternatively an attacker would have to host a malicious Web site that contained a Web 
page designed to exploit these vulnerabilities. 

As with the previous Internet Explorer cumulative patches released with bulletins MS03-004, MS03-015, 
MS03-020, and MS03-032, this cumulative patch will cause window.showHelp( ) to cease to function if you 
have not applied the HTML Help update. If you have installed the updated HTML Help control from Knowledge 
Base article 811630, you will still be able to use HTML Help functionality after applying this patch. 

In addition to applying this security patch it is recommended that users also install the Windows Media 
Player update referenced in Knowledge Base Article 828026. This update is available from Windows Update 
as well as the Microsoft Download Center for all supported versions of Windows Media Player. While not a 
security patch, this update contains a change to the behavior of Windows Media Player’s ability to launch 
URLs to help protect against DHTML behavior based attacks. Specifically, it restricts Windows Media 
Player’s ability to launch URLs in the local computer zone from other zones.


Mitigating factors:


Severity Rating:

                                                                                 Internet
 		 Internet     Internet    Internet    Internet    Internet  Explorer 6.0 for	
		 Explorer     Explorer    Explorer    Explorer    Explorer       Windows
		 5.01 SP3     5.01 SP4    5.5 SP2     6.0 Gold    6.0 SP1      Server 2003                                                       Windows 
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
   Object Tag  
vulnerability in   Critical     Critical    Critical    Critical    Critical      Moderate 
  Popup Window
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
   Object Tag 
vulnerability with Critical     Critical    Critical    Critical    Critical      Moderate 
XML data binding 		
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Aggregate Severity 
  of all issues
 included in this  Critical     Critical 	 Critical    Critical    Critical    Moderate 
      patch
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
The above assessment is based on the types of systems affected by the vulnerability, their typical 
deployment patterns, and the effect that exploiting the vulnerability would have on them. 

Vulnerability identifier:

 
Tested Versions:
Microsoft tested Internet Explorer versions 5.01 Service Pack 3, Internet Explorer 5.01 Service Pack 4, 
Internet Explorer 5.5 Service pack 2, Internet Explorer 6.0 and Internet Explorer 6.0 Service Pack 1 to 
assess whether they are affected by these vulnerabilities. Previous versions are no longer supported, 
and may or may not be affected by these vulnerabilities.


Additional information about this patch

Installation platforms: 
The patch can be installed on:


Inclusion in future service packs:
The fix for these issues will be included in Windows 2000 Service Pack 5, Windows XP Service Pack 2 and 
Windows Server 2003 Service Pack 1. 

Reboot needed: Yes - After reboot, an administrator logon is required for: 

Patch can be uninstalled: Yes. 

Superseded patches: This patch supersedes the one provided in Microsoft Security Bulletin MS03-032 
which is itself a cumulative patch. 

Verifying patch installation: 

CIAC wishes to acknowledge the contributions of Microsoft for the information contained in this bulletin.
DOE-CIRC can be contacted at:
    Voice:          +1 866-941-2472 (7 x 24)
    E-mail:          doecirc@doecirc.energy.gov
    World Wide Web:  http://www.doecirc.energy.gov/