Microsoft Confirms New IE Data Leakage Flaw
Microsoft today issued a security advisory to acknowledge an information disclosure hole in its Internet Explorer browser and warned that an attacker could exploit the flaw to access files
with an already known filename and location.
The vulnerability was first discussed at this week's Black Hat DC conference by Jorge Luis Alvarez Medina, a security consultant with Core Security Technologies. Microsoft says the risk is highest for IE users running Windows XP or who have disabled the browser's Protected Mode feature.
Editor's Pick
Medina's presentation demonstrated how an attacker can read every file of an IE user's filesystem. The attack scenario leveraged different design features of Internet Explorer that can be combined to do serious damage.
Here's more on Medina's talk from DarkReading's Kelly Jackson-Higgins:
[Medina] says popular features in IE, such as URL Security Zones and the browser's file-sharing protocol, can together be abused to execute an attack that results in the attacker being able to read all files on the victim's machine. Medina plans to release proof-of-concept code for the attack next month after Black Hat DC, and after Microsoft issues a security update for the attack, which affects IE versions 6 and above, he says.
"These vulnerabilities are just features ... the implementation of the features allow you to obtain certain information, which by itself is harmless. But when combined together with other features, it renders an attack vector," Medina says. The attack requires the user to click on a malicious link.
According to Microsoft's advisory, IE's Protected Mode prevents exploitation of this vulnerability and is running by default for versions of Internet Explorer on Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008.
The problem does affect every version of the browser and is considered most serious on Windows XP.
The vulnerability exists due to content being forced to render incorrectly from local files in such a way that information can be exposed to malicious websites.
For pre-patch mitigations, see the "workarounds" section of Microsoft's advisory.
Commenting on this Article is closed.
Most Commented Stories
-
UPDATE: Looking For a 'FireSheep' Moment, Researchers Lay Bare Woeful SCADA Security (16)
-
Video: New Banking Trojan Caught Breaking CAPTCHA (4)
-
Apple Ships Huge Set of Patches for OS X (3)
-
Update: Verisign Admits To Security Breaches in 2010 (3)
-
Market Fail: Regulations May Be Only Hope For Securing Critical Infrastructure (2)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.




