• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

New unpatched vulnerability in the Internet Explorer (mshtml.dll) found

Myantispyware team March 17, 2006    

There is a new and unpatched vulnerability with exploit code in the wild that affects the latest version of IE. The exploit works by including an abnormally large (a couple thousand) number of script actions inside a single HTML tag.

This vulnerability can be triggered by specifying more than a couple
thousand script action handlers (such as onLoad, onMouseMove, etc) for any
single HTML tag. Due to a programming error, MSIE will then attempt to
write memory array out of bounds, at an offset corresponding to the ID of
the script action handler multiplied by 4 (due to 32-bit address clipping,
the result is a small positive integer).

The list of IDs can be found on the Web, and is as follows (values in
parentheses = resulting offsets):

onhelp = 0x8001177d (+0x45df4)
onclick = 0x80011778 (+0x45de0)
ondblclick = 0x80011779 (+0x45de4)
onkeyup = 0x80011776 (+0x45dd8)
onkeydown = 0x80011775 (+0x45dd4)
onkeypress = 0x80011777 (+0x45ddc)
onmouseup = 0x80011773 (+0x45dcc)
onmousedown = 0x80011772 (+0x45dc8)
onmousemove = 0x80011774 (+0x45dd0)
onmouseout = 0x80011771 (+0x45dc4)
onmouseover = 0x80011770 (+0x45dc0)
onreadystatechange = 0x80011789 (+0x45e24)
onafterupdate = 0x80011786 (+0x45e18)
onrowexit = 0x80011782 (+0x45e08)
onrowenter = 0x80011783 (+0x45e0c)
ondragstart = 0x80011793 (+0x45e4c)
onselectstart = 0x80011795 (+0x45e54)

This will cause a memory array to write out of bounds and cause overflow in Microsoft Internet Explorer (mshtml.dll) and as result an immediate or eventual browser crash. Both McAfee and Symantec have released signatures to detect this exploit. While this is only a DoS vulnerability at the moment, there is ongoing attempts to try to use this as a vector for remote code execution.

Tested on MSIE 6.0.2900.2180.xpsp2.040806-1825 on Windows XP SP2. As far
as I can tell, other browser makes (Firefox, Opera) are not susceptible to
this attack.

Thanks to SecurityFocus

Exploits & Vulnerabilities

 Previous Post

Multiple vulnerabilities have been identified in various Macromedia products

Next Post 

Coolwebsearch.info – new site from the Coolwebsearch family

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

Leave a Reply Cancel reply

New Guides

Banana Hack Recipe For Weight Loss & Lipo Drops Reviews, Scam or Legit?
Arialief Nerve‑Health Supplement Reviews, Rachel Mathews & Dr Richard Moore?
The Bitcoin Promo Code Scam: A Look Inside Tidexcoin.com
Hunny7.com: A Task App Scam Exposed
HunnyCash.com Review, Free $100 Signup Bonus Scam Exposed

Follow Us

Search

Useful Guides

How to reset Google Chrome settings to default
Smart Captcha Virus redirect
What is a Virus that Redirects Web Pages? A Comprehensive Guide
This setting is enforced by your administrator (Removal guide)
Malwarebytes won’t install, run or update – How to fix it
Managed by your organization chrome virus
Chrome Managed by your organization malware removal guide

Recent Guides

Multiple vulnerabilities have been identified in various Macromedia products
How to remove BraveSentry
Fake Windows Sites + WMF Explot + Keyloger = New Botnet
Trojan Horse keylogger steal end-user information for popular online games.
LdPinch again spammed via ICQ

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.