Short Name |
HTTP:STC:IE:IE-MHT-REDIRECT |
---|---|
Severity |
Medium |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Internet Explorer MHT Redirect |
Release Date |
2004/09/01 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to bypass Internet Explorer's security zones. A remote user can create a page in the Internet security zone that contains an IFRAME that uses MhtRedirParsesLocalFile to parse a local file. Using a URL of the format "mhtml:url!original_url", IE attempts to download the "original_url".
A vulnerability has been in sub-frames in Microsoft Internet Explorer. Because of this, an attacker may be able to violate cross-domain policy. This could permit script code to access properties of other domains or execute in the context of the Local Zone. Exploitation of this issue in combination with other vulnerabilities could allow for execution of a malicious executable on a vulnerable system.