TUCoPS :: Browsers :: ciach038.txt

Internet Explorer 3x Vulnerabilities



                      Internet Explorer 3.x Vulnerabilities

March 10, 1997 22:00 GMT                                          Number H-38a
PROBLEM:       Arbitrary commands may be executed on a Web client system using 
               Microsoft Internet Explorer 3.x. 
PLATFORM:      Windows 95, Windows NT 4.0
DAMAGE:        A Web server can potentially destroy or manipulate data on a 
               visiting client system. 
SOLUTION:      Install the patch referenced below 
VULNERABILITY  These are potentially serious vulnerabilities that should be 
ASSESSMENT:    addressed as soon as possible. 

Several security vulnerabilities has been discovered in Microsoft Internet
Explorer 3.0 and 3.01 for Windows 95 and NT. The vulnerabilities allows an
arbitary program to be executed on a user's machine when accessing a malicious
Web site. For example, selecting a URL on a Web site could cause the standard
Windows calculator to start executing. Other programs, such as format or
deltree, might also be executed, which can be more malicious in nature.
These programs are executed without permission by the user - the standard
security mechanisms provided with Internet Explorer are bypassed completely.

These problems are unrelated to ActiveX or Java, common sources of security
concern. Rather, these vulnerabilities takes advantage of two features of the
Windows 95/NT4.0 interface - shortcuts and hyperlinks. Shortcuts are files
ending with a .LNK extension, and provide a means of referencing another
file on a system. Windows hyperlinks are files ending with a .URL extension,
and provide a quick jump to a URL on the Internet. When files of these types
are placed on a Web site, they may potentially execute an arbitary command
on the client's computer when accessed through a URL. The arbitary command
(and path to the command) must be known ahead of time, but many key system
programs are kept in standard locations, so this may be easily guessed.

Microsoft has addressed the problems with a patch on their Web site at:


CIAC wishes to acknowledge the contributions of Paul Greene, Geoggrey Elliot,
and Brian Morin of Worcester Polytechnic Institute, and Microsoft for the 
information contained in this bulletin.

