RealSecure Network, RealSecure Server Sensor, BlackICE Server Protection, BlackICE PC Protection, Proventia Network MFS, IBM Security Server Protection for Windows, Proventia-G 1.1 and earlier, Proventia Network IDS, Proventia Network IPS, Proventia Desktop, Proventia Server IPS for Linux technology, RealSecure Desktop, Virtual Server Protection for Vmware:
This signature detects an attempt to execute shell code by exploiting an error in Internet Explorer's JavaScript exception handling mechanism.
High
RealSecure Network: XPU 24.53, RealSecure Server Sensor: XPU 24.53, BlackICE Server Protection: 3.6.cpy, BlackICE PC Protection: 3.6cpy, Proventia Network MFS: XPU 1.92, IBM Security Server Protection for Windows: 1.0.914.1930, IBM Security Server Protection for Windows: 2.1.14.2400, Proventia-G 1.1 and earlier: XPU 24.53, Proventia Network IDS: XPU 24.53, Proventia Network IPS: XPU 1.92, Proventia Desktop: 1930, Proventia Server IPS for Linux technology: 1.92, RealSecure Desktop: epy, Virtual Server Protection for Vmware: 1.0
Microsoft Internet Explorer: 6.0, Microsoft Internet Explorer: 6.0 SP1, Microsoft Internet Explorer: 5.01 SP4, Microsoft Windows 2000: SP4, Microsoft Windows 2003 Server: x64, Microsoft Windows XP: SP2, Microsoft Windows 2003 Server: Itanium, Microsoft Windows 2003 Server: SP1, Microsoft Windows XP: x64 Professional, Microsoft Windows 2003 Server: SP1 Itanium
Unauthorized Access Attempt
Microsoft Internet Explorer could allow a remote attacker to execute arbitrary code on a victim's system, caused by a memory corruption vulnerability when a script error is handled. A remote attacker could exploit this vulnerability to execute arbitrary code on a victim's system with the privileges of the victim if the attacker could persuade the victim to visit a malicious Web page.
Apply the appropriate patch for your system, as listed in the latest Microsoft Security Bulletin. See References.
— OR —
Use Microsoft Automatic Update if it is supported by your operating system. The original bulletin issued by Microsoft has been superseded.
Microsoft Security Bulletin MS06-072
Cumulative Security Update for Internet Explorer (925454)
http://www.microsoft.com/technet/security/bulletin/ms06-072.mspx
Secunia Research 12/12/2006
Internet Explorer Script Error Handling Memory Corruption
http://secunia.com/secunia_research/2006-58/advisory/
IBM Internet Security Systems Protection Alert, Dec 12, 2006
Critical Vulnerabilities in MS06-072
http://www.iss.net/threats/243.html
Microsoft Security Bulletin MS07-016
Cumulative Security Update for Internet Explorer (928090)
http://www.microsoft.com/technet/security/Bulletin/ms07-016.mspx
Microsoft Security Bulletin MS07-027
Cumulative Security Update for Internet Explorer (931768)
http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx
Microsoft Security Bulletin MS07-033
Cumulative Security Update for Internet Explorer (933566)
http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx
Microsoft Security Bulletin MS07-045
Cumulative Security Update for Internet Explorer (937143)
http://www.microsoft.com/technet/security/bulletin/ms07-045.mspx
Microsoft Security Bulletin MS07-057
Cumulative Security Update for Internet Explorer (939653)
http://www.microsoft.com/technet/security/Bulletin/MS07-057.mspx
Microsoft Security Bulletin MS07-069
Cumulative Security Update for Internet Explorer (942615)
http://www.microsoft.com/technet/security/bulletin/ms07-069.mspx
Microsoft Security Bulletin MS08-010
Cumulative Security Update for Internet Explorer (944533)
http://www.microsoft.com/technet/security/bulletin/ms08-010.mspx
Microsoft Security Bulletin MS08-024
Cumulative Security Update for Internet Explorer (947864)
http://www.microsoft.com/technet/security/bulletin/ms08-024.mspx
Microsoft Security Bulletin MS08-031
Cumulative Security Update for Internet Explorer (950759)
http://www.microsoft.com/technet/security/Bulletin/MS08-031.mspx
Microsoft Security Bulletin MS08-045
Cumulative Security Update for Internet Explorer (953838)
http://www.microsoft.com/technet/security/bulletin/ms08-045.mspx
Microsoft Security Bulletin MS08-058
Cumulative Security Update for Internet Explorer (956390)
http://www.microsoft.com/technet/security/bulletin/ms08-058.mspx
ISS X-Force
Microsoft Internet Explorer script error handling code execution
http://www.iss.net/security_center/static/30600.php
CVE
CVE-2006-5579
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5579