Overview
A problem in the way Microsoft Internet Explorer handles a large number of file download requests could result in the execution of arbitrary code on a vulnerable system.
Description
When Internet Explorer (IE) follows a link to an executable file (.exe), a dialog window is displayed that prompts the user to open the file, save the file, or cancel the operation. When handling a sufficiently large number of file download requests, IE eventually fails to display the dialog window and executes the specified file without user intervention. A dialog is displayed for each download request, and it may be possible to terminate the IE process before the file is executed. Publicly available examples use large numbers of frames (FRAME or IFRAME elements) to generate download requests. Other software that uses the WebBrowser ActiveX control may be affected. |
Impact
An attacker who is able to convince a user to access a specially crafted HTML document, such as an Internet web page or HTML email message, could execute arbitrary code with the privileges of the user. Resource exhaustion caused by the large number of download requests could also cause a denial of service. |
Solution
Apply Patch |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.securityfocus.com/archive/1/320981/2003-05-06/2003-05-12/0
- http://www.securityfocus.com/archive/1/321532/2003-05-13/2003-05-19/0
- http://www.securityfocus.com/archive/1/321662/2003-05-13/2003-05-19/0
- http://www.microsoft.com/technet/security/bulletin/MS03-020.asp
- http://support.microsoft.com/default.aspx?scid=kb;en-us;818529
- http://support.microsoft.com/?kbid=182569
- http://msdn.microsoft.com/workshop/security/szone/overview/overview.asp
- http://www.secunia.com/advisories/8807/
- http://www.securityfocus.com/bid/7539
Acknowledgements
This vulnerability was publicly reported by Marek Bialoglowy.
This document was written by Art Manion.
Other Information
CVE IDs: | CVE-2003-0309 |
Severity Metric: | 51.84 |
Date Public: | 2003-05-08 |
Date First Published: | 2003-05-16 |
Date Last Updated: | 2006-12-08 20:46 UTC |
Document Revision: | 31 |