|
|
|
![]() |
Vulnerability Note VU#251788Microsoft Internet Explorer does not safely handle multiple file download requestsOverviewA problem in the way Microsoft Internet Explorer handles a large number of file download requests could result in the execution of arbitrary code on a vulnerable system.I. DescriptionWhen Internet Explorer (IE) follows a link to an executable file (.exe), a dialog window is displayed that prompts the user to open the file, save the file, or cancel the operation. When handling a sufficiently large number of file download requests, IE eventually fails to display the dialog window and executes the specified file without user intervention. A dialog is displayed for each download request, and it may be possible to terminate the IE process before the file is executed. Publicly available examples use large numbers of frames (FRAME or IFRAME elements) to generate download requests.Other software that uses the WebBrowser ActiveX control may be affected. Apply Q818529 or a more recent cumulative patch. See Microsoft Security Bulletin MS03-020 for more information.
Configure Outlook and Outlook Express to open email messages in the Restricted Sites Zone, where file downloads are disabled by default. This change can be made manually or as part of the Outlook Email Security Update for Outlook 98 and Outlook 2000. Outlook 2002 and Outlook Express 6 use the Restricted Sites Zone and by default. Note that a different vulnerability could allow the file download restriction in Outlook and Outlook Express to be bypassed. If file downloads are disabled in the zone used by Outlook and Outlook Express but enabled in the zone containing the attacker's executable file, a specially crafted email message could generate enough download requests to execute the attacker's file. It is important to disable file downloads in both the zone used by Outlook and Outlook Express and the zone(s) used by IE to browse untrusted sites. Systems Affected
References
This vulnerability was publicly reported by Marek Bialoglowy. This document was written by Art Manion.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||