NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


The First Internet Explorer 7 Vulnerability

Truth or hoax?

By Marius Oiaga, Technology News Editor

14th of December 2006, 13:43 GMT

Adjust text size:


The report of a vulnerability affecting Internet Explorer 7, in fact the first vulnerability in IE7, has been around for quite some time, but I have just came across it. In fact, the vulnerability was
initially reported on November 1, 2006. As far I was unable to confirm its authenticity from my usual sources, and this is explanatory for the subtitle. But I am also going to go on a limb and call it a hoax. I will explain why, just bear with me.

According the flaw report, Internet Explorer 7 is vulnerable to DLL-load hijacking. "When IE7 is executed it will load several DLL files. While trying to load some of those files, it does not provide the full path of the DLL file to the function which loads the DLL file to the memory, and therefore Windows will search for this file in the user's machine using the directories provided in the PATH environment variable, and will load the first match it will found," reported Aviv Raff.

In this context, for the browser to actually load a malicious DLL or the downloader DLL of a malicious file, the file in question must first of be planted via a process that bypasses the generic detection of startup folder and startup registry keys alterations by security software, in one of the PATH directories. On the next launch of Internet Explorer 7, the browser will load and execute the malicious DLL.

Let me translate this. This scenario involves an already compromised system. In fact Microsoft's response to this is: "If the attacker can put a dll on the box in a location that is in the user's PATH variable, then they already own the box." Otherwise Internet Explorer 7 is not impacted by the DLL-load hijacking vulnerability. Time is another factor. This report is over a month old and the fact that exploits are hesitating to appear is proof that IE7 DLL-load hijacking is a hoax.

Additionally, Windows would not limit the search to the directories provided in the PATH environment, but to an array of locations that differ in concordance with the enabled/disabled status of SafeDllSearchMode. These are the locations searched: the directory from which the application loaded, the system directory, the 16-bit system directory, the current directory and the directories that are listed in the PATH environment variable.

Read by 2,940 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.7/5) 4 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Internet Explorer 7 Immune to October's Vulnerabilities

Free IE6 VPC + Windows XP SP2 = a Microsoft Success

IE7 Redirected 1.2 Million Phishing Attacks in 2 Weeks

Internet Explorer 7 Down - Firefox 2.0 Up

Windows Live OneCare Updated with Anti-phishing Technology Activation

Security Vulnerabilities in Internet Explorer 7

3.06 Percent Global Share for Internet Explorer 7

Upgrade to IE7 Optimized for Google

The Internet Explorer 6 Virtual PC - Run IE6 and IE7 Side by Side

IE7 Speaks Chinese and Hebrew

Vista-ready Flash Player 9 Integrates with IE7 Protect Mode

Microsoft Removes IE7 Update from WSUS

Internet Explorer 7 - Zero Vulnerabilities

The First Update for Internet Explorer 7

Fishing Details Out of the Firefox 2.0 and IE7 Anti-Phishing Reports

Seven December 2006 Security Bulletins

PoC Available for Patched Microsoft Vulnerability

Build Your Own Customized IE7

Second Word Zero-Day Vulnerability in a Week

Inspect OS and Software Security

The Third Exploit for Microsoft Word Vulnerability

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM