Updated: Latest IE Thing: It's Not a Bug, It's a Feature
Microsoft has another IE vulnerability on its hands. But is it a flaw, or is it a feature? IE's been having a miserable time of late, starring in scads of headlines about security flaws. Most recently came last week's monthly security bulletin, a package of fixes for 20 individual problems in Microsoft products. Included in the IE bulletin were fixes for a pair of COM (Component Object Model) instantiation memory corruption vulnerabilities, and a fix for an FTP server response-parsing memory corruption issue. The issues were rated as critical in versions of the browser previous to its current IE 7 iteration, in which they rank as only "important" or "low." The latest issue, discovered by Indian security researcher Rajesh Sethumadhavan, supposedly allows for information disclosure in IE 6 or 7 when a user visits a Web site. According to an advisory posted by XDisclose, a vulnerability in IE 6 and 7 Windows Service Pack 2 leaves users who browse a malicious Web site, or who open an e-mail with a malicious HTML file, open to the exploit. XDisclose's advisory maintains that the exploit can be used to access files on an affected system's hard drive, such as bank information, which can then be displayed on a Web site. XDisclose has deemed what's it's calling a flaw to be critical. The so-called flaw has to do with the way in which IE handles different html tags. "Microsoft Windows Explorer is not handling various html tags like 'img' 'script' 'embed' 'object' 'param' 'style' 'bgsound' 'body' 'input' (Other tags may be also vulnerable). By using the file protocol along with above tags it is possible to access victims' local files," the advisory states. However, a Microsoft spokesperson told eWEEK that the company has already investigated the supposed flaw and determined that, while an attacker could detect the presence of files on an affected system, he or she wouldn't be able to receive files from that system. "In addition, the attacker must know the location of the file in advance," the spokesperson wrote in an e-mail exchange. According to the spokesperson, this behavior is by design in current versions of Internet Explorer. As far as rating its severity goes, the spokesperson said that Microsoft rates vulnerabilities as critical where that vulnerability can be used to achieve remote code execution. Since that's not the case here, it's not rated. Here's the design intent behind the behavior: "The ability to render content locally to the computer Internet Explorer is installed on, is a basic set of functionality in Internet Explorer as it allows users to view the contents of files on their system using Internet Explorer," the spokesperson said. "The fact that a remotely provided link can render the contents of files on a remote system given the exact location of that file is just using this display functionality." *Note: This posting was updated on 2/21/07 to include additional input from Microsoft on the nature of IE's behavior in this case. |


Comments (4)
"IE's been having a miserable time of late, starring in scads of headlines about security flaws."
Of course, that's a blatantly false statement. But hey, who cares about the facts?
Posted by Justice | February 21, 2007 8:23 AM
"Microsoft rates vulnerabilities as critical where that vulnerability can be used to achieve remote code execution." So if a security vulnerability enables someone to steal data from a computer, it is not CRITICAL? Hogwash! That kind of thinking is what helps the thieves steal credit card and other valuable personal data. Can someone reorient the thinking of the Microsoft spokesperson who made this inane statement, and reorient all of Microsoft as well? It is this kind of lax thinking about computer security that makes a company vulnerable to lawsuits for negligence!
Posted by Ben Myers | February 21, 2007 1:36 PM
Okay, when I visit a web site my browser can display the contents of files on my machine to me. My question is can that web site also see the contents of those files? If it can then there's a problem.
John
Posted by John Currier | February 21, 2007 4:13 PM
Typical MSFT drivel, right up there with Billy crying about the latest Mac ads. The TRUTH hurts!
Posted by cabdriver | February 25, 2007 2:40 PM