Information Disclosure Vulnerability in Microsoft Internet Explorer

A vulnerability exists in IE that can lead to information disclosure.

Ken Pfeil

February 21, 2002

2 Min Read
ITPro Today logo

ReportedFebruary 21, 2002, by Microsoft.

VERSIONSAFFECTED

  • Microsoft Internet Explorer (IE) 6.0, 5.5, and 5.01

 

DESCRIPTION

Avulnerability exists in IE that can lead to information disclosure. This problemstems from the way IE handles VBScript when validating cross-domain access,letting one domain's scripts access another domain's contents within a frame. Anattacker can use scripts to exploit the vulnerability by extracting otherdomains' frame contents to send to the attacker's Web site. The attacker canview files located on the user's local machine or capture the contents ofthird-party Web sites the user visited after leaving the attacker's site. Thevulnerability lets an intruder learn personal information about the user, suchas usernames, passwords, or credit card information.

 

VENDORRESPONSE

Thevendor, Microsoft, has released SecurityBulletin MS02-009,which addresses this vulnerability, and recommends that affected users apply theappropriate patch listed at Microsoft's Download Center or at the WindowsUpdate Web site.

 

CREDIT
Discoveredby ZentaiPeter Aron of Ivy Hungary Ltd

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like