| PROBLEM: | There are 3 vulnerabilities in Microsoft Internet Explorer: 1) A navigation method cross-domain vulnerability; 2) A malformed BMP file buffer overrun vulnerability; and 3) A malformed GIF file double free vulnerability. |
| PLATFORM: | Microsoft Windows NTฎ Workstation 4.0 Service Pack 6a Microsoft Windows NT Server 4.0 Service Pack 6a Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4 Microsoft Windows XP and Microsoft Windows XP Service Pack 1 Microsoft Windows XP 64-Bit Edition Service Pack 1 Microsoft Windows XP 64-Bit Edition Version 2003 Microsoft Windows Serverฎ 2003 Microsoft Windows Server 2003 64-Bit Edition Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (Me) Review the FAQ section of this bulletin for details about these operating systems. |
| SOFTWARE: | Internet Explorer 5.01 Service Pack 2 Internet Explorer 5.01 Service Pack 3 Internet Explorer 5.01 Service Pack 4 Internet Explorer 5.5 Service Pack 2 Internet Explorer 6 Internet Explorer 6 Service Pack 1 Internet Explorer 6 Service Pack 1 (64-Bit Edition) Internet Explorer 6 for Windows Server 2003 Internet Explorer 6 for Windows Server 2003 (64-Bit Edition) |
| DAMAGE: | An attacker could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. |
| SOLUTION: | Apply the update immediately. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. A remote attacker may execute code with privileges of the logged on user, by hosting a malicious website and enticing a user to view the site or access the site via an HTML email message. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/o-191.shtml |
| ORIGINAL BULLETIN: | Microsoft Security Bulletin MS04-025 http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx |
| CVE/CAN: | http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CAN-2004-0549 CAN-2004-0566 CAN-2003-1048 |
REVISION HISTORY:
8/2/04 - On Aug. 1, 2004, Microsoft revised the Caveats section to reflect
availability of a new version of the update for Windows XP customers
running Windows Update Version 5.
[***** Start Microsoft Security Bulletin MS04-025 *****]
Microsoft Security Bulletin MS04-025
Cumulative Security Update for Internet Explorer (867801)
Issued: July 30, 2004
Version: 1.0
Summary
Who should read this document: Customers who use Microsoftฎ Internet Explorer
Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Recommendation: Customers should apply the update immediately.
Security Update Replacement: This update replaces the one that is provided in Microsoft Security
Bulletin MS04-004, which is itself a cumulative update.
Caveats:
Subsequent to the release of this security bulletin, Microsoft was made aware
that the update provided for Windows XP customers running the new version of
Windows Update, Windows Update Version 5, did not contain the final release
code for the vulnerabilities addressed in the security bulletin. Microsoft
has corrected the update and is re-releasing this bulletin to advise of the
availability of a revised update available to Windows Update Version 5 customers.
Customers who are utilizing Windows Update Version 4, the vast majority of
customers, are not affected by this revision.
This update does not include hotfixes for Internet Explorer provided since the release of
MS04-004. Customers who have received hotfixes from Microsoft or their support providers since the release
of MS04-004 should review the FAQ section for this update to determine how this update might impact their
operating systems.
Tested Software and Security Update Download Locations:
Affected Software:
Microsoft Windows NTฎ Workstation 4.0 Service Pack 6a
Microsoft Windows NT Server 4.0 Service Pack 6a
Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6
Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 S
ervice Pack 4
Microsoft Windows XP and Microsoft Windows XP Service Pack 1
Microsoft Windows XP 64-Bit Edition Service Pack 1
Microsoft Windows XP 64-Bit Edition Version 2003
Microsoft Windows Serverฎ 2003
Microsoft Windows Server 2003 64-Bit Edition
Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition
(Me) Review the FAQ section of this bulletin for details about these operating systems.
Tested Microsoft Windows Components:
Affected Components:
Internet Explorer 5.01 Service Pack 2: Download the update.
Internet Explorer 5.01 Service Pack 3: Download the update.
Internet Explorer 5.01 Service Pack 4: Download the update.
Internet Explorer 5.5 Service Pack 2: Download the update.
Internet Explorer 6: Download the update.
Internet Explorer 6 Service Pack 1: Download the update.
Internet Explorer 6 Service Pack 1 (64-Bit Edition): Download the update.
Internet Explorer 6 for Windows Server 2003: Download the update.
Internet Explorer 6 for Windows Server 2003 (64-Bit Edition): Download the update.
The software in this list has been tested to determine if the versions are affected. Other versions either
no longer include security update support or may not be affected. To determine the support lifecycle for
your product and version, visit the following Microsoft Support Lifecycle Web site.
General Information
Executive Summary
Executive Summary:
This update resolves several newly discovered public vulnerabilities. Each vulnerability is documented in
this bulletin in its own Vulnerability Details section.
If a user is logged on with administrative privileges, an attacker who successfully exploited the most
severe of these vulnerabilities could take complete control of an affected system, including installing
programs; viewing, changing, or deleting data; or creating new accounts with full privileges. Users whose
accounts are configured to have fewer privileges on the system would be at less risk than users who operate
with administrative privileges.
Microsoft recommends that customers apply the update immediately.
Severity Ratings and Vulnerability Identifiers:
| Vulnerability Identifiers | Impact of Vulnerability | Internet Explorer 5.01 SP2, SP3, SP4 | Internet Explorer 5.5 SP2 | Internet Explorer 6 | Internet Explorer 6 SP1 (All versions earlier than Windows Server 2003) | Internet Explorer 6 for Windows Server 2003 (including 64-bit Edition) |
Navigation Method Cross-Domain Vulnerability - CAN-2004-0549 | Remote Code Execution | None | Critical | Critical | Critical | Moderate |
Malformed BMP File Buffer Overrun Vulnerability | Remote Code Execution | Critical | Critical | Critical | None | None |
Malformed GIF File Double Free Vulnerability - CAN-2003-1048 | Remote Code Execution | Critical | Critical | Critical | Critical | Critical |
Aggregate Severity of All Vulnerabilities |
| Critical | Critical | Critical | Critical | Critical |
This assessment is based on the types of systems that are affected by the vulnerability, their typical deployment patterns, and the effect that exploiting the vulnerability would have on them.
Frequently asked questions (FAQ) related to this security update Vulnerability Details Security Update Information Installation Platforms and Prerequisites: For additional information about how to determine which version of Internet Explorer you are running, click the following article number to view the article in the Microsoft Knowledge Base: 164539 How to Determine Which Version of Internet Explorer Is Installed For information about the specific security update for your platform, click the appropriate link:
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org