Third Party Offers Patch for IE Hole

By Nate Mook | Published March 28, 2006, 11:16 AM

While Microsoft debates whether to release a critical update for Internet Explorer before the next Patch Tuesday on April 11, security firm eEye Digital Security has released its own patch. The flaw, discovered last week, puts IE users at risk of code execution simply by visiting a malicious Web site.

A problem exists in how IE interprets the "createTextRange()" method used for radio button controls in HTML forms. From there, the flaw can be exploited to allow program flow to be redirected to the heap. When this occurs, the attacker can then exploit the vulnerability to execute code on an affected computer.

The vulnerability has been given a high severity rating by a number of security firms including eEye, which recommends that users disable Active Scripting from within Internet Explorer. However, the company is also offering a temporary patch for those organizations that require the feature.

The downloadable fix from eEye blocks access to the component within IE that is vulnerable, preventing malicious sites from exploiting the problem to install a backdoor or other malware.

"This workaround is not meant to replace the forthcoming Microsoft patch, rather it is intended as a temporary protection against this flaw," eEye says in its advisory. "Organizations that choose to employ this workaround should take the steps required to uninstall it once the official Microsoft patch is released."

eEye released a similar unofficial patch following the discovery of a security vulnerability in Windows Meta File (WMF) image handling last December. The high-profile flaw and subsequent exploits forced Microsoft to release an official fix out of schedule.

However, the new flaw appears to be much less widespread, according to Microsoft, and other security firms are not recommending eEye's fix. eEye initially held back the source code to the patch, but later posted it online following criticism by security experts.

Microsoft says it is "actively keeping an eye on any attempts to utilize this in an attack" and will release a patch sooner if deemed necessary. It recommends that users wait for the official update or disable Active Scripting entirely.

"We cannot recommend third party solutions that modify the way the product itself operates," said Mike Reavey from Microsoft's Security Response Center. "The reason is really around the fact that we carefully review and test our security updates to ensure that they are of high quality and have been evaluated thoroughly for application compatibility."

"Customers of course can weigh the risk of deploying a third party 'patch' but it's unclear what impact this will have on the system," Reavey added.

Comments

View comments by with a score of at least

My friend got hit with a Trojan Monday and it had to be from this IE Hole. I blogged it at www.msmvps.com/shelluser. The machine is full patched and had NAV 2005 on it. I put Windows OneCare on it because NAV failed to catch the file the magically apeared on the desktop!

Score: 0

|

"The machine is full patched and had NAV 2005 on it"

Right, because nothing malicious can ever get past NAV 2005 :D

Score: 0

|

There's also an unofficial patch/feature-disabling-workaround available at:

http://www.determina.com...isory_march272006_1.asp

Score: 0

|

=/

Could that really be called a patch?

Sounds a heck of a lot like a feature-disabling workaround to me. And, it's only temporary. I'm not complaining or anything, but give credit where credit is due. And when it's not due... don't?

...or maybe I'm just nit-picking.

Score: 0

|

I have got the very best fix for the problem.Don't use it.

Score: 0

|

Or use an alternative browser. Done deal.

Score: 0

|

While I hate MS and the idea of having to wait for a known bug to be fixed as much as the next guy, most of you forget why MS created patch Tuesday.

Its so admins of large networks can expect patches on one day of the month, instead of scrambling to patch 500 machines every week or two whenever a new bug fix is out.

Problem is some of these nasty bugs are found within a week or so after patch Tuesday, so over the next 3+ weeks there is time for sites to abuse these security holes. It might only take MS a few days to make the patch, but they are going to wait a couple weeks until Patch Tuesday even if it is ready, which is why companies are starting to create their own like this.

Score: 0

|

"most of you forget why MS created patch Tuesday."

I thought it was because MS was sick of all the bad press every time a single patch became available (1 critical patch out of the blue = important breaking news report) and so made this a 'feature' (7 critical patches on a single day in a regular schedule = minor news report). Admittedly it was a pain for sysadmins to deal with a trickle of patches, but a regular weekly patch release would have been much better from a security POV. They even could have done it such that non-critical patches were only released once a month but had a separate weekly critical cycle. But they didn't.

Score: 0

|

It's so comforting to know that Microsoft cares so much about it's customers that they are willing to wait to see if a few of their lab rats get exploited before fixing a problem that was found beforehand.

Score: 0

|

oh yeah, and it's chaos in the world right now because of all the people and machines affected by this .... i might not even get paid on friday since everyone in the world is suffering by this flaw ..... oh the horror !!!!!!!!!!

*** cricket !! cricket !! ***

Score: 0

|

I don't know what anyone's talking about, I haven't seen this exploi@#$WERWF@#R@R@#R@CRWWR2


23r 23
4234
234

NO CARRIER

(heh)

Score: 0

|

It's sad to see that a 3rd party has to come up with a patch while the guys and gals at MS are still debating about it...

Score: 0

|

Not sure if SAD is the correct word. What will eEye Digital Security do when MS patches? Are they going to claim that they cannot use it because it is theirs? :)

Score: 0

|

read the article dips***:

The downloadable fix from eEye blocks access to the component within IE that is vulnerable, preventing malicious sites from exploiting the problem to install a backdoor or other malware.

"This workaround is not meant to replace the forthcoming Microsoft patch, rather it is intended as a temporary protection against this flaw," eEye says in its advisory. "Organizations that choose to employ this workaround should take the steps required to uninstall it once the official Microsoft patch is released."

Score: 0

|

Hey, atleast they provide a fix while MS is still at the debating stage!!!!

I guess you shouldn't be calling me names but MS.

Score: 0

|

This isn't the first time 3rd parties have released patches. How pathetic. I know MS has to test, but they really should only need a day to write the test, and a day to test the patch. They have billions in cash, surely they have billions of ways to test a patch quickly?

Score: 0

|

they have more to lose though if something goes wrong than random firm xyz. given the magnitude of windows and ie's deep integration with it, it's not in microsoft's best interest to rush out a patch given what could go wrong.

besides ... you also need to read the article:

The downloadable fix from eEye blocks access to the component within IE that is vulnerable, preventing malicious sites from exploiting the problem to install a backdoor or other malware.

"This workaround is not meant to replace the forthcoming Microsoft patch, rather it is intended as a temporary protection against this flaw," eEye says in its advisory. "Organizations that choose to employ this workaround should take the steps required to uninstall it once the official Microsoft patch is released."

Score: 0

|

I cannot believe that MS is so retarded and slow that a 3rd party has to release a patch for IE.

Hahahahha.

Yeah....I really want Vista.....yeah.........yeah that's it.

Score: 0

|

damn it ... don't any of you read the article???

Score: 0

|

"While Microsoft debates whether to release a critical update for Internet Explorer before the next Patch Tuesday on April 11..."

No offence Nate, but at this point I don't think Microsoft is "debating" releasing the security patch before patch Tuesday, as it is likely not finished yet anyway. Until they actually finish testing the patch they cannot debate it much.

I could be wrong. I think MS would release an official patch before patch tuesday if it were ready before then--if nothing else to prevent naysayers from overhyping the "problems" of having patch Tuesdays and such.

Score: 0

|

the 19 sites that have been identified as exploiting the flaw, should be public humiliated as well as any others that try.

MS has only so many fingers to plug holes with and much larger fish to fry at any given point.

Score: 0

|

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Microsoft's .NET Micro Framework is now free and open source

The latest version of Microsoft's .NET Micro framework is now in the hands of the FOSS community.

Google's value proposition for Chrome OS: Should we feel insulted?

For a search engine that has direct access to all the world's online history, it appears to have taught Google nothing about selling a machine.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.

AOL's spinoff from Time Warner to shed 2,500 jobs

As AOL moves toward become an independent company again, it will cut nearly a third of its workforce.

PDC 2009: Microsoft cares about Web browser performance

The effort to give users of the world's dominant Web browser the impression of quality, is a personal one for the man who leads that battle.