Microsoft Internet Explorer external cached object DOM access
| ie-cache-external-dom-access (10433) |
Description:
Microsoft Internet Explorer could allow a remote attacker to execute malicious JavaScript in restricted domains by using the external cached object to bypass security domain restrictions and access any page's Document Object Model (DOM). If a remote attacker creates a malicious Web page that opens a window on the attacker's own site that uses the affected cached object, but then changes the URL of the window to a victim's page, the cached object could be used to bypass restrictions and access the victim page's DOM. This vulnerability could allow an attacker to steal cookies from Web sites, gain access to Web site content, and read files or execute program's on the victim's computer.
Platforms Affected:
- Microsoft, Internet Explorer 5.5
- Microsoft, Internet Explorer 6 SP1
- Microsoft, Internet Explorer 6
Remedy:
Apply the appropriate patch for your system, as listed in the latest Microsoft Security Bulletin. See References.
— OR —
Use Microsoft Automatic Update if it is supported by your operating system. The original bulletin issued by Microsoft has been superseded.
Consequences:
Gain Access
References:
- CIAC Information Bulletin N-021, Microsoft Cumulative Patch for Internet Explorer at http://www.ciac.org/ciac/bulletins/n-021.shtml.
- GreyMagic Security Advisory GM#012-IE, Vulnerable cached objects in IE (9 advisories in 1) at http://sec.greymagic.com/adv/gm012-ie/.
- Microsoft Security Bulletin MS02-068, Cumulative Patch for Internet Explorer (324929) at http://www.microsoft.com/technet/security/bulletin/ms02-068.mspx.
- Microsoft Security Bulletin MS03-004, Cumulative Patch for Internet Explorer (810847) at http://www.microsoft.com/technet/security/bulletin/ms03-004.mspx.
- Microsoft Security Bulletin MS03-015, Cumulative Patch for Internet Explorer (813489) at http://www.microsoft.com/technet/security/bulletin/ms03-015.mspx.
- Microsoft Security Bulletin MS03-020, Cumulative Patch for Internet Explorer (818529) at http://www.microsoft.com/technet/security/bulletin/ms03-020.mspx.
- Microsoft Security Bulletin MS03-032, Cumulative Patch for Internet Explorer (822925) at http://www.microsoft.com/technet/security/bulletin/ms03-032.mspx.
- Microsoft Security Bulletin MS03-040, Cumulative Patch for Internet Explorer (828750) at http://www.microsoft.com/technet/security/bulletin/ms03-040.mspx.
- Microsoft Security Bulletin MS03-048, Cumulative Security Update for Internet Explorer (824145) at http://www.microsoft.com/technet/security/bulletin/ms03-048.mspx.
- Microsoft Security Bulletin MS04-004, Cumulative Security Update for Internet Explorer (832894) at http://www.microsoft.com/technet/security/bulletin/ms04-004.mspx.
- Microsoft Security Bulletin MS04-025, Cumulative Security Update for Internet Explorer (867801) at http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx.
- Microsoft Security Bulletin MS04-038, Cumulative Security Update for Internet Explorer (834707) at http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx.
- Microsoft Security Bulletin MS04-040, Cumulative Security Update for Internet Explorer (889293) at http://www.microsoft.com/technet/security/bulletin/ms04-040.mspx.
- Microsoft Security Bulletin MS05-014, Cumulative Security Update for Internet Explorer (867282) at http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx.
- Microsoft Security Bulletin MS05-020, Cumulative Security Update for Internet Explorer (890923) at http://www.microsoft.com/technet/security/Bulletin/MS05-020.mspx.
- Microsoft Security Bulletin MS05-025, Cumulative Security Update for Internet Explorer (883939) at http://www.microsoft.com/technet/security/bulletin/ms05-025.mspx.
- Microsoft Security Bulletin MS05-038, Cumulative Security Update for Internet Explorer (896727) at http://www.microsoft.com/technet/security/bulletin/ms05-038.mspx.
- Microsoft Security Bulletin MS05-052, Cumulative Security Update for Internet Explorer (896688) at http://www.microsoft.com/technet/security/Bulletin/MS05-052.mspx.
- Microsoft Security Bulletin MS05-054, Cumulative Security Update for Internet Explorer (905915) at http://www.microsoft.com/technet/security/Bulletin/MS05-054.mspx.
- Microsoft Security Bulletin MS06-004, Cumulative Security Update for Internet Explorer (910620) at http://www.microsoft.com/technet/security/Bulletin/MS06-004.mspx.
- Microsoft Security Bulletin MS06-013, Cumulative Security Update for Internet Explorer (912812) at http://www.microsoft.com/technet/security/Bulletin/MS06-013.mspx.
- Microsoft Security Bulletin MS06-021, Cumulative Security Update for Internet Explorer (916281) at http://www.microsoft.com/technet/security/Bulletin/MS06-021.mspx.
- Microsoft Security Bulletin MS06-042, Cumulative Security Update for Internet Explorer (918899) at http://www.microsoft.com/technet/security/bulletin/ms06-042.mspx.
- Microsoft Security Bulletin MS06-067, Cumulative Security Update for Internet Explorer (922760) at http://www.microsoft.com/technet/security/bulletin/ms06-067.mspx.
- Microsoft Security Bulletin MS06-072, Cumulative Security Update for Internet Explorer (925454) at http://www.microsoft.com/technet/security/Bulletin/MS06-072.mspx.
- Microsoft Security Bulletin MS07-016, Cumulative Security Update for Internet Explorer (928090) at http://www.microsoft.com/technet/security/Bulletin/ms07-016.mspx.
- Microsoft Security Bulletin MS07-027, Cumulative Security Update for Internet Explorer (931768) at http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx.
- Microsoft Security Bulletin MS07-033, Cumulative Security Update for Internet Explorer (933566) at http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx.
- Microsoft Security Bulletin MS07-045, Cumulative Security Update for Internet Explorer (937143) at http://www.microsoft.com/technet/security/bulletin/ms07-045.mspx.
- Microsoft Security Bulletin MS07-057, Cumulative Security Update for Internet Explorer (939653) at http://www.microsoft.com/technet/security/Bulletin/MS07-057.mspx.
- Microsoft Security Bulletin MS07-069, Cumulative Security Update for Internet Explorer (942615) at http://www.microsoft.com/technet/security/bulletin/ms07-069.mspx.
- Microsoft Security Bulletin MS08-010, Cumulative Security Update for Internet Explorer (944533) at http://www.microsoft.com/technet/security/bulletin/ms08-010.mspx.
- Microsoft Security Bulletin MS08-024, Cumulative Security Update for Internet Explorer (947864) at http://www.microsoft.com/technet/security/bulletin/ms08-024.mspx.
- Microsoft Security Bulletin MS08-031, Cumulative Security Update for Internet Explorer (950759) at http://www.microsoft.com/technet/security/Bulletin/MS08-031.mspx.
- Microsoft Security Bulletin MS08-045, Cumulative Security Update for Internet Explorer (953838) at http://www.microsoft.com/technet/security/bulletin/ms08-045.mspx.
- Microsoft Security Bulletin MS08-058, Cumulative Security Update for Internet Explorer (956390) at http://www.microsoft.com/technet/security/bulletin/ms08-058.mspx.
- NTBugTraq Mailing List, Mon, 25 Nov 2002 19:07:32 +0200, Re: MS02-066 - fixes, gaps and incorrect statements at http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0211&L=ntbugtraq&F=P&S=&P=2428.
- NTBugTraq Mailing List, Thu, 5 Dec 2002 14:42:08 +0100, Notes on MS02-068, extensive downplaying of severity at http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0212&L=ntbugtraq&F=P&S=&P=1332.
- BID-6028: Multiple Microsoft Internet Explorer Cached Objects Zone Bypass Vulnerability
- CVE-2002-1254: Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka Cross Domain Verification via Cached Methods.
- CVE-2002-1262: Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files.
- US-CERT VU#162097: Microsoft Internet Explorer does not adequately validate references to cached objects and methods
Reported:
Oct 22, 2002
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
