TITLE: Internet Explorer MHTML Protocol Handler Cross-Domain Information Disclosure SECUNIA ADVISORY ID: SA31415 VERIFY ADVISORY: http://secunia.com/advisories/31415/ CRITICAL: Moderately critical IMPACT: Exposure of sensitive information WHERE: From remote SOFTWARE: Microsoft Internet Explorer 7.x http://secunia.com/product/12366/ Microsoft Internet Explorer 6.x http://secunia.com/product/11/ Microsoft Internet Explorer 5.01 http://secunia.com/product/9/ DESCRIPTION: A vulnerability has been reported in Internet Explorer, which can be exploited by malicious people to gain knowledge of sensitive information. The vulnerability is caused due to an error in the MHTML protocol handler when interpreting MHTML URI redirections. This can be exploited to bypass Internet Explorer domain restrictions when returning MHTML content via a specially crafted web page. Successful exploitation allows reading content from another Internet Explorer domain or the local system NOTE: The vulnerability is reported in Outlook Express and Windows Mail by Microsoft vulnerability as the functionality is provided by these programs. However, the vulnerability is exploitable via Internet Explorer. SOLUTION: Apply patches. -- Outlook Express 5.5 SP2 -- Windows 2000 SP4: http://www.microsoft.com/downloads/details.aspx?FamilyId=6257bfae-35f0-4c0e-b960-bca7aa6f86f7 -- Outlook Express 6 SP1 -- Windows 2000 SP4: http://www.microsoft.com/downloads/details.aspx?FamilyId=dab178f7-c282-41f4-acb1-a86e6aa4c91b -- Microsoft Outlook Express 6 -- Windows XP SP2/SP3: http://www.microsoft.com/downloads/details.aspx?FamilyId=91469f2f-461c-4a67-8738-d42520427f6b Windows XP Professional x64 Edition (optionally with SP2): http://www.microsoft.com/downloads/details.aspx?FamilyId=2220aece-79d2-426f-90ec-24a17470567a Windows Server 2003 SP1/SP2: http://www.microsoft.com/downloads/details.aspx?FamilyId=30f2244a-f6fd-4fc1-a871-abf6958cb660 Windows Server 2003 x64 Edition (optionally with SP2): http://www.microsoft.com/downloads/details.aspx?FamilyId=3287f006-cbb2-4c6d-820c-32833e08035a Windows Server 2003 with SP1/SP2 for Itanium-based Systems: http://www.microsoft.com/downloads/details.aspx?FamilyId=c8570e40-355b-4a9b-933d-53ae021cbda5 -- Windows Mail -- Windows Vista (optionally with SP1): http://www.microsoft.com/downloads/details.aspx?FamilyId=3851bcf8-f971-4d38-b27f-97396854aac0 Windows Vista x64 Edition (optionally with SP1): http://www.microsoft.com/downloads/details.aspx?FamilyId=3bf7eb8a-b347-4661-be2d-682adc713769 Windows Server 2008 for 32-bit Systems: http://www.microsoft.com/downloads/details.aspx?FamilyId=dc3c4b63-acd3-4469-8d47-e0562d99ee65 Windows Server 2008 for x64-based Systems: http://www.microsoft.com/downloads/details.aspx?FamilyId=5f973f54-2322-4b41-8c1a-3e712c0da8ae Windows Server 2008 for Itanium-based Systems: http://www.microsoft.com/downloads/details.aspx?FamilyId=9226cd85-1445-4976-a126-757c5d142ffd ORIGINAL ADVISORY: MS08-048 (KB951066): http://www.microsoft.com/technet/security/Bulletin/MS08-048.mspx ========================= The list's FAQ's can be seen by sending an email to PCWorks-request@xxxxxxxxxxxxx with FAQ in the subject line. To unsubscribe, subscribe, set Digest or Vacation to on or off, go to //www.freelists.org/list/pcworks . You can also send an email to PCWorks-request@xxxxxxxxxxxxx with Unsubscribe in the subject line. Your member list settings can be found at //www.freelists.org/cgi-bin/lsg2.cgi/l=pcworks . Once logged in, you have access to numerous other email options. The list archives are located at //www.freelists.org/archives/pcworks/ . All email posted to the list will be placed there in the event anyone needs to look for previous posts. -zxdjhu-