Check Point Reference: | CPAI-2009-279 |
Date Published: | 15 Dec 2009 |
Severity: | High |
Last Updated: | Thursday 01 January, 2009 |
Source: | Microsoft Security Bulletin MS08-031 |
Industry Reference: | CVE-2008-1544 |
Protection Provided by: | |
Who is Vulnerable? | Internet Explorer 5.01 and Internet Explorer 6 SP1: Microsoft Windows 2000 SP4 Microsoft Windows 2000 SP4 Internet Explorer 6: Windows XP SP2 Windows XP SP3 Windows XP Professional x64 Edition Windows XP Professional x64 Edition SP2 Windows Server 2003 SP1 Windows Server 2003 SP2 Windows Server 2003 x64 Edition Windows Server 2003 x64 Edition SP2 Windows Server 2003 with SP1 (Itanium) Windows Server 2003 with SP2 (Itanium) Internet Explorer 7: Windows XP SP2 Windows XP SP3 Windows XP Professional x64 Edition Windows XP Professional x64 Edition SP2 Windows Server 2003 SP1 Windows Server 2003 SP2 Windows Server 2003 x64 Edition Windows Server 2003 x64 Edition SP2 Windows Server 2003 with SP1 (Itanium) Windows Server 2003 with SP2 (Itanium) Windows Vista Windows Vista SP1 Windows Vista x64 Edition Windows Vista x64 Edition SP1 Windows Server 2008 for 32-bit Systems Windows Server 2008 for x64-based Systems Windows Server 2008 (Itanium) |
Vulnerability Description | An information disclosure vulnerability has been reported in the way that Internet Explorer handles certain request headers. A remote attacker could exploit this issue by convincing a user to open a maliciously crafted HTML file with Internet Explorer, which may allow the attacker to view data from a Web page in another Internet Explorer domain. |
Update/Patch Avaliable | Apply patches: Microsoft Security Bulletin MS08-031 |
Vulnerability Details | The vulnerability is due to an error in Internet Explorer that incorrectly parses a specially crafted request header, allowing a violation of the same origin policy. To trigger this issue, an attacker may create a malicious web page and persuade a user to view it. Successful exploitation of this vulnerability will allow an attacker to view the content in another browser window in another domain or Internet Explorer zone. |