Categories: US-Cert-Repository

Cross-Domain Vulnerability in Internet Explorer


Systems Affected

  • Microsoft Windows systems

Overview

Microsoft Internet Explorer (IE) contains a flaw that could allow attackers to run programs of their choice on your computer.

Description

Microsoft IE uses a cross-domain security model to separate content from different sources. A flaw in the model makes IE vulnerable to a cross-domain violation. Attackers could exploit this flaw to execute programs on your computer.

Resolution

Apply a patch

Micrososft has released a patch to resolve this issue. It is available from Microsoft Windows Update or Microsoft Security Bulletin MS04-025.

Disable Active scripting and ActiveX controls

Instructions for disabling Active scripting and ActiveX controls in the Internet Zone can be found in the Malicious Web Scripts FAQ.

Do not follow unsolicited links

Do not click on unsolicited URLs received in email, instant messages, web forums, or internet relay chat (IRC) channels.

Run and maintain an antivirus product

It is important that you use antivirus software and keep it up to date. Most antivirus software vendors frequently release updated information, tools, or virus databases to help detect and recover from virus infections. Many antivirus packages support automatic updates of virus definitions. US-CERT recommends using these automatic updates when possible.

References

  • US-CERT Technical Alert TA04-163A – <http://www.us-cert.gov/cas/techalerts/TA04-163A.html>
  • Vulnerability Note VU#713878 – <http://www.kb.cert.org/vuls/id/713878>
  • Microsoft Windows Update – <http://windowsupdate.microsoft.com/>
  • Microsoft Security Bulletin MS04-025 – <http://www.microsoft.com/technet/security/bulletin/MS04-025.mspx>
  • Malicious Web Scripts FAQ – <http://www.cert.org/tech_tips/malicious_code_FAQ.html>
  • Protect Your PC – <http://www.microsoft.com/security/protect/default.asp>
  • Increase Your Browsing and E-Mail Safety – <http://www.microsoft.com/security/incident/settings.mspx>

Author: Michael Durkota

Copyright 2004 Carnegie Mellon University. Terms of use

Revision History

  • June 11, 2004: Initial release
    July 30, 2004: Added patch information and links to MS04-025

Last updated 



Source link

admin

Share
Published by
admin

Recent Posts

MyDoom.B Virus

Systems Affected   Any system running Microsoft Windows (Windows 95 and newer) that are used…

1 month ago

Multiple Vulnerabilities in Microsoft Internet Explorer

Systems Affected   Microsoft Windows systems running Internet Explorer 5.01 Internet Explorer 5.50 Internet Explorer…

1 month ago

HTTP Parsing Vulnerabilities in Check Point Firewall-1

Systems Affected   Check Point Firewall-1 NG FCS Check Point Firewall-1 NG FP1 Check Point…

1 month ago

Multiple Vulnerabilities in Microsoft Windows

Systems Affected   Systems running Microsoft Windows   Overview   Microsoft Windows contains multiple vulnerabilities,…

1 month ago

Vulnerability in Microsoft Outlook 2002

Systems Affected   Systems running Microsoft Office XP and Outlook 2002   Overview   There…

1 month ago

This website uses cookies.