Overview
Microsoft Internet Explorer does not properly display the location of HTML documents. An attacker could exploit this behavior to mislead users into revealing sensitive information.
Description
Web browsers frequently display the Uniform Resource Locator (URL) in the address bar. Users expect this information to indicate the source of the current browser frame. Microsoft Internet Explorer (IE) does not properly display URLs that contain certain non-printable characters. IE may connect to one address but display a different address. Per RFC 2396, the URL scheme for HTTP is represented as |
Impact
An attacker could convince a user that they were viewing a legitimate site when in fact they are visiting a site controlled by the attacker. The attacker could use additional social engineering techniques to trick the victim into disclosing sensitive information such as credit card numbers, account numbers, and passwords. |
Solution
Apply patch Apply the patch (832894) referenced in Microsoft Security Bulletin MS04-004 or a more recent IE cumulative patch. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.securityfocus.com/archive/1/346948
- http://lists.netsys.com/pipermail/full-disclosure/2003-December/014663.html
- http://lists.netsys.com/pipermail/full-disclosure/2003-December/014794.html
- http://lists.netsys.com/pipermail/full-disclosure/2003-December/014796.html
- http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0312&L=ntbugtraq&F=P&S=&P=6444
- http://www.ietf.org/rfc/rfc1738.txt
- http://www.ietf.org/rfc/rfc2396.txt
- http://www.webopedia.com/TERM/p/phishing.html
- http://www.antiphishing.org/phishing_archive.htm
- http://www.secunia.com/advisories/10395/
- http://secunia.com/internet_explorer_address_bar_spoofing_test/
- http://www.securityfocus.com/bid/9182
- http://xforce.iss.net/xforce/xfdb/13935
- http://xforce.iss.net/xforce/alerts/id/159
- http://www.securiteam.com/windowsntfocus/5UP0P0AAKK.html
- http://support.microsoft.com/?id=833786
- http://support.microsoft.com/?id=834489
- http://support.microsoft.com/?id=200351
- http://support.microsoft.com/?id=832414
- http://support.microsoft.com/?id=831167
- http://www.microsoft.com/security/incident/spoof.asp
Acknowledgements
This vulnerability was publicly reported by Zap The Dingbat.
This document was written by Art Manion and Shawn Hernan.
Other Information
CVE IDs: | CVE-2003-1025 |
Severity Metric: | 14.29 |
Date Public: | 2003-12-09 |
Date First Published: | 2003-12-20 |
Date Last Updated: | 2004-02-17 22:58 UTC |
Document Revision: | 66 |