Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:IE:IE-MHT-REDIRECT

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Internet Explorer MHT Redirect

Release Date

2004/09/01

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Internet Explorer MHT Redirect


This signature detects attempts to bypass Internet Explorer's security zones. A remote user can create a page in the Internet security zone that contains an IFRAME that uses MhtRedirParsesLocalFile to parse a local file. Using a URL of the format "mhtml:url!original_url", IE attempts to download the "original_url".

Extended Description

A vulnerability has been in sub-frames in Microsoft Internet Explorer. Because of this, an attacker may be able to violate cross-domain policy. This could permit script code to access properties of other domains or execute in the context of the Local Zone. Exploitation of this issue in combination with other vulnerabilities could allow for execution of a malicious executable on a vulnerable system.

Affected Products

  • Microsoft Internet Explorer 5.0
  • Microsoft Internet Explorer 5.0.1
  • Microsoft Internet Explorer 5.0.1 SP1
  • Microsoft Internet Explorer 5.0.1 SP2
  • Microsoft Internet Explorer 5.0.1 SP3
  • Microsoft Internet Explorer 5.0.1 SP4
  • Microsoft Internet Explorer 5.5
  • Microsoft Internet Explorer 5.5 SP1
  • Microsoft Internet Explorer 5.5 SP2
  • Microsoft Internet Explorer 6.0
  • Microsoft Internet Explorer 6.0 SP1

References

  • BugTraq: 9109
  • CVE: CVE-2003-1026
  • URL: http://www.us-cert.gov/cas/techalerts/TA04-033A.html
  • URL: http://www.securitytracker.com/alerts/2003/Nov/1008292.html
  • URL: http://www.microsoft.com/technet/security/bulletin/ms04-004.asp

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out