MA-208.012010: MyCERT Alert - Critical Vulnerability in Microsoft Internet Explorer Date First Published: 2010-01-15 Date Updated: 2010-01-21 Date Last Updated: 2010-01-22 1.0 Introduction A critical vulnerability (CVE-2010-0249) has been identified in the Microsoft Internet Explorer web browser. The vulnerability, if successfully exploited will cause the application to crash and could potentially allow an attacker to take control of the affected system. This vulnerability occurs when an invalid pointer to an object may be accessed after the object has been deleted. Essentially, an attacker can trick users into clicking on a URL, which has been sent via e-mail, and this will direct the users to a specially crafted web page containing the exploit. MyCERT is aware that a '0-day' exploit is available on the internet at the time of the publication of this advisory. 2.0 Impact An attacker who successfully exploits this vulnerability will be able to execute codes remotely and gain the same privilege as the user. Unsuccessful attacks may cause denial-of-service (DoS) outcomes. 3.0 Affected Products The detail list of the vulnerable products and versions are as below: - Microsoft Internet Explorer 6
- Microsoft Internet Explorer 6 Service Pack 1
Based on the testing that was conducted in our lab, the exploit will cause Microsoft Internet Explorer 7 and 8 to crash. 4.0 Recommendations As of the writing of this advisory, Microsoft has not released any security patches for this vulnerability. However, users can use the following steps as a temporary workaround if they need to use Microsoft Internet Explorer: - Disable Active Script support in the browser. Active Script can be disabled by referring to the following steps:
On the Tools menu, click Internet Options 
Click the Security tab, choose Internet zone and click on Custom Level 
Disable the Active Scripting and click OK
Do not browse to untrusted websites or click on untrusted links especially URLs enclosed in e-mails from an unknown sender.
Browse the Internet through access of a lower privilege user to minimize the impact of the malicious file.
Consider using alternative web browsers to browse the Internet. Please make sure you use the latest version and stay up-to-date as well.
MyCERT would like to advise the users of Microsoft Internet Explorer to be vigilant of the latest security announcements by Microsoft and ensure that they automatically update the operating systems. The article on how to enable the auto update feature in Microsoft is available at the following URL: Users may also consider using a vulnerability management tool such as Secunia to ensure that all applications are updated: Microsoft has released an Out-of-Band security update for this issue on January 21, 2010. Users are highly encouraged to download the patch for their specific browser version and operating system from the following URL: Users who have already disabled the Active Script as mentioned in our workaround steps above need to enable it back. MyCERT can be reached through the following channels for further assistance: E-mail : mycert@mycert.org.my Phone : +603 89926969 or 1-300-88-2999 (monitored during business hours) Fax : +603 89453442 Handphone : +60 19 2665850 (24x7 call incident reporting) SMS : +60 19 2813801 (24x7 SMS reporting) Business Hours : Mon - Fri 08:30 -17:30 MYT Web: http://www.mycert.org.my 5.0 References |