51839 : Microsoft IE Document Object Handling Memory Corruption Arbitrary Code Execution
Printer | http://osvdb.org/51839 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
21 4748 over 2 years ago about 1 year ago 21 times 100%

Timeline

Vendor Informed Date Disclosure Date Vendor Solution Date
2008-09-23 2009-02-10 2009-02-10
Time to Patch
140 days

Keywords

TippingPoint IPS Digital Vaccine protection filter ID 6753

Description

A memory corruption flaw exists in Internet Explorer. The program fails to validate web page content resulting in memory corruption. With a specially crafted web page, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required, Remote / Network Access, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public, Exploit Private, Exploit Commercial
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation
Watch-list
Internet Explorer
Watch-list
7

References

Tools & Filters

35630

Credit

CVSSv2 Score

CVSSv2 Base Score = 9.3
Source: nvd.nist.gov | Generated: 2009-02-11 | Disagree? | There are 1 more: View All

Access_vector_2 Access_complexity_1 Authentication_2 Confidentiality_impact_2 Integrity_impact_2 Availability_impact_2

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

2009/03/22 02:17:51 | Sphere | Search

from: Microsoft Patch Watch

last 24 hours or last 7 days sorted by. Researcher upset by Windows DNS patch … MS09-002 - Cumulative Security Update for Internet Explorer (961260) MS09-0. See original discussion:Sphere | Search

2009/02/19 18:51:00 | Targeted malware attacks exploiting IE7 flaw detected

from: TECHBLOG.RANDTENTERPRISES.COM

Researchers at TrendMicro have detected a targeted malware attack exploiting last week’s patched critical MS09-002 vulnerability affecting ... Micro Smart Protection Network as HTML_DLOADER.AS. HTML_DLOADER.AS exploits the CVE-2009-0075

2009/03/02 23:19:00 | Client Side exploit Delivery - Word files

from: Laramies Corner

Today i will do a brief post about how you can deliver an exploit URL to your target. I was reading the SANS storm post about MS09-002 XML/DOC initial infection vector ... penetration test when you need to perform a targeted client side attack, fire up Metasploit, setup MS09-002

2009/02/24 08:43:24 | Microsoft Internet Explorer Object Clone Deletion Memory Corruption (MS09-002) Proof-of-Concept exploit

from: Recognize-Security

[ Microsoft Internet Explorer]Here’s a proof-of-concept exploit for Microsoft Internet Explorer Object Clone Deletion Memory Corruption vulnerability in case you don’t use the Metasploit Framework and still want to test it. Like the Metasploit module I wrote for it, it has been tested successfully on Windows XP SP3,

2009/03/04 20:51:00 | MS Internet Explorer 7 Memory Corruption Exploit (MS09-002) (fast)

from: Exploits and Vulnerabilities container

# # Author : Ahmed Obied (ahmed.obied@gmail.com) # # - Based on the code found by str0ke in the wild for MS09-002 # - Tested using Internet Explorer 7.0.5730.11 on Windows XP SP2 # # Usage

2009/03/03 08:16:07 | BigPond = bad net citizen

from: Simon's Space

In BigPond’s March 2009 newsletter, Ponderings, was this little piece: AUTO UPDATES EAT USAGE The ‘Auto Update’ function in a lot of software, ... of just 1 update. MS09-002 – addresses a vulnerability in Microsoft Internet Explorer (KB 961260) Let’

2009/02/27 16:36:09 | MS09-002 exploit(IE7) Exposed Owning LAN for Pentesters

from: Wireless hack,Wifi hack & security

Lol in my last video i showed how to use MS09-002 exploit ,but in that there was a problem where the Vulnerable URL should be Opened by the enduser but how to do without sending links to them

2009/02/20 00:01:00 | Malware crooks were quick to develop MS09-002 exploit

from: Shoaib Yousuf

MS09-002 Exploit in the wild uses MSWord Lure An exploit found to be targeting a recently patched vulnerability for Internet Explorer 7 was ... the MS09-002 exploit . Malware authors are always working to create new and improved ways to evade ... to the malicious website to launch and execute the MS09-002 exploit . For those

2009/02/19 22:33:53 | Should MSFT Rethink the IE Patching Cycle?

from: The Laws of Vulnerabilities

The browser is the most popular used application to access the Internet ... of their public release (see MS09-002). ms09_002.png We believe that IE patches are well

2009/02/19 02:00:54 | MS09-002 ITW Exploit

from: ThreatFire Research Blog

The IE7 vulnerability recently patched by Microsoft's MS09-002 is being exploited in the wild. The ThreatFire community is not seeing much of the attack, but ThreatFire prevents attacks against the memory corruption (referenced in CVE-2009-0075) in Internet Explorer 7's loaded mshtml.dll

2009/02/17 12:59:00 | Targeted Malware Attacks Exploiting Internet Explorer 7 Vulnerability

from: CyberInsecure.com

Researchers at TrendMicro have detected a targeted malware attack exploiting last week’s patched critical MS09-002 vulnerability affecting Internet ... as HTML_DLOADER.AS.HTML_DLOADER.AS exploits the CVE-2009-0075 vulnerability, which is already

2009/02/18 03:17:33 | Hackers attack IE7 flaw

from: .::anti-abuse.com::.

Iain Thomson in San Francisco, vnunet.com , Wednesday 18 February 2009 at 02:11: ... exploits in the wild. We can confirm this – the exploit for the CVE-2009-0075 vulnerability (Uninitialized

2009/02/17 12:10:03 | Zero Day For IE7 Being used in the wild.

from: Tech-Linkblog.com

It looks like IE7 patches are being used right now in the wild.  According to TrendMicro : HTML_DLOADER.AS exploits the CVE-2009-0075 vulnerability , which is already addressed by the MS09-002 security patch released last week. On an unpatched system though, successful exploitation by HTML_DLOADER.AS

2009/02/11 12:24:47 | Feb09 Security Bulletin SDL Benefit Summary

from: Jeff Jones Security Blog

Summaries from previous months: Jan09 Security Bulletin SDL Benefit Summary When I do analysis and reports on ... Benefit Comment Non-Windows Product CVE-2009-0075 C-NA

2009/02/19 07:46:02 | Microsoft Internet Explorer 7 Vulnerability Being Exploited

from: Technical Support News

US-CERT, the government’s cyber security arm, is warning users of Microsoft Internet Explorer 7 about a Trend Micro report claiming that ... Security Bulletin MS09-002 to be “critical” and gave the vulnerability a score ... an ActiveX control that reaches out to a malicious site that exploits the vulnerability patched by MS09-002

2009/02/19 15:05:51 | Have you patched Internet Explorer 7 yet?

from: Graham Cluley's blog

Have you patched Internet Explorer 7 yet? We're seeing evidence of a vulnerability in Internet Explorer 7 being exploited in the wild. The vulnerability (known as MS09-002) allows malicious webpages to run code on your computer which could, of course, infect your PC, commandeer your computer to be part of a botnet, or steal

2009/02/18 12:31:35 | Targeted malware attacks exploiting IE7 flaw detected

from: The Small Big Thing From Tech

Researchers at TrendMicro have detected a targeted malware attack exploiting last week’s patched critical MS09-002 vulnerability affecting ... Protection Network as HTML_DLOADER.AS. HTML_DLOADER.AS exploits the CVE-2009-0075 vulnerability, which

2009/02/17 11:15:12 | [MS Security Bulletin] Minor Revisions Issued: February 16, 2009

from: Blogs - MSMVPS.COM

[MS Security Bulletin] Minor Revisions Issued: February 16, 2009 Summary ======= The following bulletins have undergone a minor revision increment. Please see the appropriate bulletin for more details.   * MS09-002 – Critical Bulletin Information: ============== * MS09-002 - Critical   - http://www.microsoft... Posted to Cliff Hobbs

2009/02/17 11:15:12 | [MS Security Bulletin] Minor Revisions Issued: February 16, 2009

from: Cliff Hobbs at myITforum.com

Summary ======= The following bulletins have undergone a minor revision increment. Please see the appropriate bulletin for more details.   * MS09-002 – Critical Bulletin Information: ============== * MS09-002 - Critical   - http://www.microsoft.com/technet/security/bulletin/ms09-002.mspx   - Reason for Revision: V1.1 (February 16

2009/02/11 11:58:00 | February 2009 Black Tuesday Report - Critical Exchange Server Patch

from: Doing Time

We interrupt our regularly scheduled Valentine's Day Spam Countdown for an important message about Microsoft Black Tuesday ... -up patch. This one is MS09-002 and has two new ways for website authors to add code to their web

2009/02/12 16:15:21 | Re: MS09-002 Problems

from: Microsoft Patch Watch

[crosspost to Windows Update newsgroup] Error message after you install a Windows Internet Explorer 7 update from Windows Update or from Microsoft ... Update: “Webpage cannot be displayed”: link If tweaking your third-party firewall’s settings don’t help, try the following:Go here to read the rest:Re: MS09-002 Problems

2009/02/12 08:02:53 | MS09-002/MS09-004, Consistent Exploit Code Likely

from: http://f-secure.com/weblog

MS09-002/MS09-004, Consistent Exploit Code Likely Posted by Sean @ 12: ... Assessments of 1 — Consistent exploit code likely. First there's MS09-002 which addresses two vulnerabilities in Internet Explorer 7. MS09-002 And then there is MS09-004 which patches a vulnerability

2009/02/11 06:37:46 | Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 Service Pack 2 (KB961260)

from: Microsoft Patch Watch

This update addresses the vulnerability discussed in Microsoft Security Bulletin MS09-002. To find out if other security updates are available for you, see the Additional Information section

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use