Vulnerability Note VU#652278
Microsoft Internet Explorer does not properly display URLs
Overview
Microsoft Internet Explorer does not properly display the location of HTML documents. An attacker could exploit this behavior to mislead users into revealing sensitive information.
Description
Web browsers frequently display the Uniform Resource Locator (URL) in the address bar. Users expect this information to indicate the source of the current browser frame. Microsoft Internet Explorer (IE) does not properly display URLs that contain certain non-printable characters. IE may connect to one address but display a different address. Per RFC 2396, the URL scheme for HTTP is represented as
|
Impact
An attacker could convince a user that they were viewing a legitimate site when in fact they are visiting a site controlled by the attacker. The attacker could use additional social engineering techniques to trick the victim into disclosing sensitive information such as credit card numbers, account numbers, and passwords. |
Solution
Apply patch
|
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft Corporation | Affected | 09 Dec 2003 | 02 Feb 2004 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.us-cert.gov/cas/techalerts/TA04-033A.html
- http://www.us-cert.gov/cas/alerts/SA04-033A.html
- http://www.securityfocus.com/archive/1/346948
- http://lists.netsys.com/pipermail/full-disclosure/2003-December/014663.html
- http://lists.netsys.com/pipermail/full-disclosure/2003-December/014794.html
- http://lists.netsys.com/pipermail/full-disclosure/2003-December/014796.html
- http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0312&L=ntbugtraq&F=P&S=&P=6444
- http://www.ietf.org/rfc/rfc1738.txt
- http://www.ietf.org/rfc/rfc2396.txt
- http://www.webopedia.com/TERM/p/phishing.html
- http://www.antiphishing.org/phishing_archive.htm
- http://www.secunia.com/advisories/10395/
- http://secunia.com/internet_explorer_address_bar_spoofing_test/
- http://www.securityfocus.com/bid/9182
- http://xforce.iss.net/xforce/xfdb/13935
- http://xforce.iss.net/xforce/alerts/id/159
- http://www.securiteam.com/windowsntfocus/5UP0P0AAKK.html
- http://support.microsoft.com/?id=833786
- http://support.microsoft.com/?id=834489
- http://support.microsoft.com/?id=200351
- http://support.microsoft.com/?id=832414
- http://support.microsoft.com/?id=831167
- http://www.microsoft.com/security/incident/spoof.asp
Credit
This vulnerability was publicly reported by Zap The Dingbat.
This document was written by Art Manion and Shawn Hernan.
Other Information
- CVE IDs: CAN-2003-1025
- Date Public: 09 Dec 2003
- Date First Published: 19 Dec 2003
- Date Last Updated: 17 Feb 2004
- Severity Metric: 14.29
- Document Revision: 65
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.