SecurityFocus Microsoft Newsletter #417

[email protected] 23 Oct 2008 20:10:32 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #417
----------------------------------------

This issue is sponsored by HP:

Very few applications are bulletproof from hackers. During this 12 minute=
 unscripted video, you.ll sit in a virtual conference room with two of th=
e world's most well-known white hat hackers, Caleb Sima and Billy Hoffman=
.=20
During this whiteboard session, they demonstrate just how easy it is to b=
reak-into a private corporate network through the web application and own=
 the back-end database. During this video, you will learn just how easy i=
t is to hack into web applications and hear how hackers execute some of t=
heir favorite attacks: client side pricing attack, session hijacking, fuz=
zing and SQL Injection.
https://h30406.www3.hp.com/campaigns/2008/wwcampaign/1-4W4AD/index.php?mc=
c=3DDZRV&jumpid=3Dedm_r11374_us/en/large/tsg/w1_Hackers_vid_securityfocus=
/mcc_DZRV/20081020/


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Clicking to the Past
       2. The Vice of Vice Presidential E-Mail
II.  MICROSOFT VULNERABILITY SUMMARY
       1. SilverSHielD 'opendir()' Remote Denial of Service Vulnerability
       2. Microsoft Windows Server Service RPC Handling Remote Code Execu=
tion Vulnerability
       3. freeSSHd SFTP 'rename' Remote Buffer Overflow Vulnerability
       4. Multiple EMC NetWorker Products 'nsrexecd.exe' RPC Request Deni=
al of Service Vulnerability
       5. Cisco PIX and ASA Windows NT Domain VPN Authentication Bypass V=
ulnerability
       6. IBM DB2 Universal Database Prior to 9.1 Fixpak 6 Multiple Vulne=
rabilities
       7. Wireshark 1.0.3 Multiple Denial Of Service Vulnerabilities
       8. Hummingbird HostExplorer ActiveX Control 'PlainTextPassword()' =
Buffer Overflow Vulnerability
       9. Adobe Flash CS3 Professional SWF File Heap Buffer Overflow Vuln=
erability
       10. Symantec Altiris Deployment Solution Client User Interface Loc=
al Privilege Escalation Vulnerability
       11. Microsoft Outlook Web Access for Exchange Server 'redir.asp' U=
RI Redirection Vulnerability
       12. Titan FTP Server 'SITE WHO' Command Remote Denial of Service V=
ulnerability
       13. Etype Eserv FTP 'ABOR' Command Remote Stack Based Buffer Overf=
low Vulnerability
       14. Husdawg System Requirements Lab Multiple Remote Code Execution=
 Vulnerabilities
       15. RaidenFTPD 'MLST' Command Remote Stack Based Buffer Overflow V=
ulnerability
       16. XM Easy Personal FTP Server 'NSLT' Command Remote Denial of Se=
rvice Vulnerability
       17. Lenovo Rescue and Recovery 'tvtumon.sys' Heap Overflow Vulnera=
bility
       18. Microsoft Excel Formula Parsing Remote Code Execution Vulnerab=
ility
       19. Microsoft Excel BIFF File Format Parsing Remote Code Execution=
 Vulnerability
       20. Microsoft Excel Calendar Object Validation Remote Code Executi=
on Vulnerability
       21. Microsoft Office CDO Protocol Cross Site Scripting Vulnerabili=
ty
       22. Microsoft Windows Internet Printing Service Integer Overflow V=
ulnerability
       23. Microsoft Windows VAD Local Privilege Escalation Vulnerability
       24. Microsoft Windows AFD Driver Local Privilege Escalation Vulner=
ability
       25. Microsoft Internet Explorer Cross Domain Information Disclosur=
e Vulnerability
       26. Microsoft Windows Kernel Unhandled System Call Local Privilege=
 Escalation Vulnerability
       27. Microsoft Windows Kernel Memory Corruption Local Privilege Esc=
alation Vulnerability
       28. Microsoft Windows Kernel Window Creation Local Privilege Escal=
ation Vulnerability
       29. Microsoft Windows SMB Buffer Underflow Code Execution Vulnerab=
ility
       30. Microsoft Message Queuing Service RPC Query Heap Corruption Vu=
lnerability
       31. Microsoft Host Integration Server RPC Remote Command Execution=
 Vulnerability
       32. Microsoft Internet Explorer HTML Objects Uninitialized Memory =
Corruption Vulnerability
       33. Microsoft Internet Explorer Uninitialized Object Remote Memory=
 Corruption Vulnerability
       34. Microsoft Internet Explorer Event Handling Cross Domain Securi=
ty Bypass Vulnerability
       35. Microsoft Internet Explorer HTML Element Cross Domain Security=
 Bypass Vulnerability
       36. Microsoft Windows Active Directory LDAP Request Handling Remot=
e Code Execution Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #416
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Clicking to the Past
By Chris Wysopal
When the first details trickled out about a new attack, dubbed .clickjack=
ing. by the researchers who found it, the descriptions made me think of t=
he tricks I used to pull during penetration tests ten years ago to get ad=
ministrator privileges: Tricking the user into issuing a command on an at=
tacker.s behalf is one of the oldest attack vectors in the book.=20
http://www.securityfocus.com/columnists/483

2a .The Vice of Vice Presidential E-Mail
By Mark Rasch
Is it a crime to read someone else's e-mail without their consent? Seems =
like a simple question, but the law is not so clear. In mid-September 200=
8, a hacker using the handle "Rubico" claim credit for breaking into the =
Yahoo! e-mail account of Governor Sarah Palin, the Republican Vice Presid=
ential candidate. In a post online, Rubico wrote that he had been followi=
ng news reports that claimed Palin had been using her personal Yahoo e-ma=
il account for official government business.
In the early 90's, I attended an academic conference in Hawaii. At one pr=
esentation, a colleague from the University of California at Berkeley who=
m I'll refer to as "the supervisor," told a story of young hackers, who h=
e referred to as the Urchins
http://www.securityfocus.com/columnists/482


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. SilverSHielD 'opendir()' Remote Denial of Service Vulnerability
BugTraq ID: 31884
Remote: Yes
Date Published: 2008-10-23
Relevant URL: http://www.securityfocus.com/bid/31884
Summary:
SilverSHielD is prone to a denial-of-service vulnerability because the ap=
plication fails to handle excessive user input.

An attacker may exploit this issue to crash the vulnerable application, r=
esulting in a denial-of-service condition.

 SilverSHielD 1.0.2.34 is vulnerable; other versions may also be affected=
.

2. Microsoft Windows Server Service RPC Handling Remote Code Execution Vu=
lnerability
BugTraq ID: 31874
Remote: Yes
Date Published: 2008-10-22
Relevant URL: http://www.securityfocus.com/bid/31874
Summary:
Microsoft Windows is prone to a remote-code execution vulnerability that =
affects RPC (Remote Procedure Call) handling in the Server service.

An attacker could exploit this issue to execute arbitrary code with SYSTE=
M-level privileges. Successful exploits will result in the complete compr=
omise of vulnerable computers.  This issue may be prone to widespread aut=
omated exploits.  Attackers require authenticated access on Windows Vista=
 and Server 2008 platforms to exploit this issue.

This vulnerability affects Windows 2000, Windows XP, Windows Server 2003,=
 Windows Vista, and Windows Server 2008.

3. freeSSHd SFTP 'rename' Remote Buffer Overflow Vulnerability
BugTraq ID: 31872
Remote: Yes
Date Published: 2008-10-22
Relevant URL: http://www.securityfocus.com/bid/31872
Summary:
freeSSHd is prone to a remote buffer-overflow vulnerability because the a=
pplication fails to perform adequate boundary-checks on user-supplied dat=
a.=20

An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the affected application. Failed exploit atte=
mpts will result in a denial-of-service condition.

This issue affects freeSSHd 1.2.1; other versions may also be affected.

4. Multiple EMC NetWorker Products 'nsrexecd.exe' RPC Request Denial of S=
ervice Vulnerability
BugTraq ID: 31866
Remote: Yes
Date Published: 2008-10-22
Relevant URL: http://www.securityfocus.com/bid/31866
Summary:
Multiple EMC NetWorker products are prone to a denial-of-service vulnerab=
ility.

Attackers can exploit this issue by sending malicious RPC requests, causi=
ng affected applications to consume resources until they become unrespons=
ive.  Repeated requests can lead to a denial-of-service condition.

5. Cisco PIX and ASA Windows NT Domain VPN Authentication Bypass Vulnerab=
ility
BugTraq ID: 31864
Remote: Yes
Date Published: 2008-10-22
Relevant URL: http://www.securityfocus.com/bid/31864
Summary:
Cisco PIX and ASA is prone to an authentication-bypass vulnerability.=20

Remote attackers can exploit this issue to gain unauthorized access to th=
e affected devices. Successfully exploiting this issue will lead to other=
 attacks.=20

This issue is being monitored by Cisco Bug ID CSCsj25896.

6. IBM DB2 Universal Database Prior to 9.1 Fixpak 6 Multiple Vulnerabilit=
ies
BugTraq ID: 31856
Remote: Yes
Date Published: 2008-10-21
Relevant URL: http://www.securityfocus.com/bid/31856
Summary:
IBM DB2 Universal Database is prone to multiple vulnerabilities.

Successful exploits may allow attackers to obtain sensitive information o=
r cause a denial-of-service condition.

Versions prior to DB2 9.1 Fixpak 6 are affected.

7. Wireshark 1.0.3 Multiple Denial Of Service Vulnerabilities
BugTraq ID: 31838
Remote: Yes
Date Published: 2008-10-20
Relevant URL: http://www.securityfocus.com/bid/31838
Summary:
Wireshark is prone to multiple denial-of-service vulnerabilities.

Exploiting these issue may allow attackers to crash the application or ca=
use the application to crash, denying service to legitimate users. Attack=
ers may be able to leverage some of these vulnerabilities to execute arbi=
trary code, but this has not been confirmed.

These issues affect Wireshark 0.10.3 up to and including 1.0.3.

8. Hummingbird HostExplorer ActiveX Control 'PlainTextPassword()' Buffer =
Overflow Vulnerability
BugTraq ID: 31783
Remote: Yes
Date Published: 2008-10-16
Relevant URL: http://www.securityfocus.com/bid/31783
Summary:
Hummingbird HostExplorer  ActiveX control is prone to a buffer-overflow v=
ulnerability because the application fails to adequately check boundaries=
 on user-supplied input.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the application using the ActiveX control (typically Internet Explo=
rer).  Failed attacks will likely cause denial-of-service conditions.

9. Adobe Flash CS3 Professional SWF File Heap Buffer Overflow Vulnerabili=
ty
BugTraq ID: 31769
Remote: Yes
Date Published: 2008-10-15
Relevant URL: http://www.securityfocus.com/bid/31769
Summary:
Adobe Flash CS3 Professional is prone to a heap-buffer overflow vulnerabi=
lity.

An attacker may exploit this issue to execute arbitrary code in the conte=
xt of the affected application. Failed exploit attempts will likely resul=
t in denial-of-service conditions.

Flash CS3 Professional for Microsoft Windows is vulnerable.

10. Symantec Altiris Deployment Solution Client User Interface Local Priv=
ilege Escalation Vulnerability
BugTraq ID: 31766
Remote: No
Date Published: 2008-10-20
Relevant URL: http://www.securityfocus.com/bid/31766
Summary:
Symantec Altiris Deployment Solution is prone to a local privilege-escala=
tion vulnerability.

An attacker can exploit this issue to bypass security settings and gain p=
rivileged access. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.

11. Microsoft Outlook Web Access for Exchange Server 'redir.asp' URI Redi=
rection Vulnerability
BugTraq ID: 31765
Remote: Yes
Date Published: 2008-10-15
Relevant URL: http://www.securityfocus.com/bid/31765
Summary:
Outlook Web Access is prone to a remote URI-redirection vulnerability bec=
ause the application fails to properly sanitize user-supplied input.=20

A successful exploit may aid in phishing attacks.

OWA 6.5 SP 2 is vulnerable; other versions may also be affected.

12. Titan FTP Server 'SITE WHO' Command Remote Denial of Service Vulnerab=
ility
BugTraq ID: 31757
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31757
Summary:
Titan FTP Server is prone to a remote denial-of-service vulnerability.

Exploiting this issue allows remote attackers to crash affected FTP serve=
rs, denying service to legitimate users.

Titan FTP Server 6.26 build 630 is vulnerable; other versions may also be=
 affected.

13. Etype Eserv FTP 'ABOR' Command Remote Stack Based Buffer Overflow Vul=
nerability
BugTraq ID: 31753
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31753
Summary:
Etype Eserv is prone to a remote stack-based buffer-overflow vulnerabilit=
y.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.

Eserv 3.26 is vulnerable; other versions may also be affected.

14. Husdawg System Requirements Lab Multiple Remote Code Execution Vulner=
abilities
BugTraq ID: 31752
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31752
Summary:
Husdawg System Requirements Lab ActiveX controls and Java applets are pro=
ne to multiple remote code-execution vulnerabilities.

Successful exploit will allow attackers to download and execute arbitrary=
 files on the affected computer in the context of the application that us=
es the plugins.

15. RaidenFTPD 'MLST' Command Remote Stack Based Buffer Overflow Vulnerab=
ility
BugTraq ID: 31741
Remote: Yes
Date Published: 2008-10-13
Relevant URL: http://www.securityfocus.com/bid/31741
Summary:
RaidenFTPD is prone to a remote stack-based buffer-overflow vulnerability=
.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.

RaidenFTPD 2.4 build 3620 is vulnerable; other versions may also be affec=
ted.

16. XM Easy Personal FTP Server 'NSLT' Command Remote Denial of Service V=
ulnerability
BugTraq ID: 31739
Remote: Yes
Date Published: 2008-10-13
Relevant URL: http://www.securityfocus.com/bid/31739
Summary:
XM Easy Personal FTP Server is prone to a remote denial-of-service vulner=
ability.

This issue allows remote attackers to crash affected FTP servers, denying=
 service to legitimate users.

XM Easy Personal FTP Server 5.6.0 is vulnerable; other versions may also =
be affected.

17. Lenovo Rescue and Recovery 'tvtumon.sys' Heap Overflow Vulnerability
BugTraq ID: 31737
Remote: No
Date Published: 2008-10-13
Relevant URL: http://www.securityfocus.com/bid/31737
Summary:
Lenovo Rescue and Recovery is prone to a heap-based overflow vulnerabilit=
y.

A successful exploit of this vulnerability can allow a local attacker to =
completely compromise the affected computer.

Lenovo Rescue and Recover 4.20 is vulnerable.

18. Microsoft Excel Formula Parsing Remote Code Execution Vulnerability
BugTraq ID: 31706
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31706
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application.

19. Microsoft Excel BIFF File Format Parsing Remote Code Execution Vulner=
ability
BugTraq ID: 31705
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31705
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application.

20. Microsoft Excel Calendar Object Validation Remote Code Execution Vuln=
erability
BugTraq ID: 31702
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31702
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application.

21. Microsoft Office CDO Protocol Cross Site Scripting Vulnerability
BugTraq ID: 31693
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31693
Summary:
Microsoft Office is prone to a cross-site scripting vulnerability that ar=
ises because the software fails to handle specially crafted CDO protocol =
URIs in a proper manner.

Successfully exploiting this issue may allow an attacker to execute arbit=
rary script code in the browser of an unsuspecting user in the context of=
 the affected site. This may allow the attacker to steal cookie-based aut=
hentication credentials and to launch other attacks.

Office XP Service Pack 3 is vulnerable.

22. Microsoft Windows Internet Printing Service Integer Overflow Vulnerab=
ility
BugTraq ID: 31682
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31682
Summary:
Microsoft Internet Printing Service is prone to an integer-overflow vulne=
rability.

Exploiting this vulnerability allows attackers to execute arbitrary code =
with system-level privileges.

23. Microsoft Windows VAD Local Privilege Escalation Vulnerability
BugTraq ID: 31675
Remote: No
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31675
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
because of an error in how the system memory manager handles memory alloc=
ation in relation to Virtual Address Descriptors (VAD).=20

A successful exploit will let a local attacker completely compromise an a=
ffected computer.

24. Microsoft Windows AFD Driver Local Privilege Escalation Vulnerability
BugTraq ID: 31673
Remote: No
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31673
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
in the Ancillary Function Driver ('afd.sys').

A successful exploit of this vulnerability will let a local attacker comp=
letely compromise an affected computer.

25. Microsoft Internet Explorer Cross Domain Information Disclosure Vulne=
rability
BugTraq ID: 31654
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31654
Summary:
Microsoft Internet Explorer is prone to a cross-domain information-disclo=
sure vulnerability because the application fails to properly enforce the =
same-origin policy.

An attacker can exploit this issue to execute arbitrary script code in an=
other browser window's security zone. This may allow the attacker to stea=
l cookie-based authentication credentials and launch other attacks.

26. Microsoft Windows Kernel Unhandled System Call Local Privilege Escala=
tion Vulnerability
BugTraq ID: 31653
Remote: No
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31653
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
that occurs in the Windows kernel.

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.

27. Microsoft Windows Kernel Memory Corruption Local Privilege Escalation=
 Vulnerability
BugTraq ID: 31652
Remote: No
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31652
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
that occurs in the Windows kernel.

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.

28. Microsoft Windows Kernel Window Creation Local Privilege Escalation V=
ulnerability
BugTraq ID: 31651
Remote: No
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31651
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability.=
=20

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.

29. Microsoft Windows SMB Buffer Underflow Code Execution Vulnerability
BugTraq ID: 31647
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31647
Summary:
Microsoft Windows is prone to a remote code execution vulnerability cause=
d by a buffer-underflow condition in the SMB (Server Message Block) proto=
col implementation.

To exploit the issue, an attacker must first successfully authenticate as=
 a legitimate user or a Guest user on the affected computer. A successful=
 exploit will completely compromise the affected computer.

30. Microsoft Message Queuing Service RPC Query Heap Corruption Vulnerabi=
lity
BugTraq ID: 31637
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31637
Summary:
The Microsoft Message Queuing service (MSMQ) is prone to a remote heap-co=
rruption vulnerability.

An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges, facilitating the complete compromise of an affected com=
puter. Failed exploit attempts will result in a denial-of-service conditi=
on.  =20

This issue is exploitable remotely on Windows 2000 systems only. The MSMQ=
 service is not installed or enabled by default. For  a computer to be ex=
ploited, an administrator must have explicitly installed and enabled the =
service.

31. Microsoft Host Integration Server RPC Remote Command Execution Vulner=
ability
BugTraq ID: 31620
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31620
Summary:
Microsoft Windows is prone to a remote command-execution vulnerability in=
 the SNA service through a remote procedure call (RPC).

Successfully exploiting this issue would allow an attacker to execute arb=
itrary commands on an affected computer in the context of the affected se=
rvice.

32. Microsoft Internet Explorer HTML Objects Uninitialized Memory Corrupt=
ion Vulnerability
BugTraq ID: 31618
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31618
Summary:
Microsoft Internet Explorer is prone to a remote memory-corruption vulner=
ability.=20

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.

33. Microsoft Internet Explorer Uninitialized Object Remote Memory Corrup=
tion Vulnerability
BugTraq ID: 31617
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31617
Summary:
Microsoft Internet Explorer is prone to a remote memory-corruption vulner=
ability.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.

34. Microsoft Internet Explorer Event Handling Cross Domain Security Bypa=
ss Vulnerability
BugTraq ID: 31616
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31616
Summary:
Microsoft Internet Explorer is prone to a cross-domain security-bypass vu=
lnerability because the application fails to properly enforce the same-or=
igin policy.

An attacker can exploit this issue to execute arbitrary script code in an=
other browser window's security zone. This may allow attackers to steal c=
ookie-based authentication credentials and launch other attacks.

NOTE: Attackers exploiting this issue on Internet Explorer 6 SP1 running =
on Microsoft Windows 2000 SP4 may leverage the issue to execute remote co=
de. Other vulnerable versions of the browser are prone only to informatio=
n disclosure.

35. Microsoft Internet Explorer HTML Element Cross Domain Security Bypass=
 Vulnerability
BugTraq ID: 31615
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31615
Summary:
Microsoft Internet Explorer is prone to a cross-domain security-bypass vu=
lnerability because the application fails to properly enforce the same-or=
igin policy.

An attacker can exploit this issue to execute arbitrary script code in an=
other browser window's security zone. This may allow attackers to steal c=
ookie-based authentication credentials and launch other attacks.

NOTE: Attackers exploiting this issue on Internet Explorer 6 SP1 running =
on Microsoft Windows 2000 SP4 may leverage the issue to execute remote co=
de. Other vulnerable versions of the browser are prone only to informatio=
n disclosure.

36. Microsoft Windows Active Directory LDAP Request Handling Remote Code =
Execution Vulnerability
BugTraq ID: 31609
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31609
Summary:
Microsoft Windows Active Directory is prone to a remote code-execution vu=
lnerability that arises because the application fails to handle specially=
 crafted LDAP or LDAP over SSL (LDAPS) requests in a proper manner.

Successfully exploiting this issue would allow an attacker to execute arb=
itrary code and gain complete access to a vulnerable computer. The attack=
er may also be able to cause the affected system to stop responding to fu=
rther requests and restart.

This issue affects only Windows 2000 servers configured as Active Directo=
ry domain controllers.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #416
http://www.securityfocus.com/archive/88/497456

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by HP:

Very few applications are bulletproof from hackers. During this 12 minute=
 unscripted video, you.ll sit in a virtual conference room with two of th=
e world's most well-known white hat hackers, Caleb Sima and Billy Hoffman=
.=20
During this whiteboard session, they demonstrate just how easy it is to b=
reak-into a private corporate network through the web application and own=
 the back-end database. During this video, you will learn just how easy i=
t is to hack into web applications and hear how hackers execute some of t=
heir favorite attacks: client side pricing attack, session hijacking, fuz=
zing and SQL Injection.
https://h30406.www3.hp.com/campaigns/2008/wwcampaign/1-4W4AD/index.php?mc=
c=3DDZRV&jumpid=3Dedm_r11374_us/en/large/tsg/w1_Hackers_vid_securityfocus=
/mcc_DZRV/20081020/