French Security Incident Response Team :

French Security Incident Response Team : "Msdds.dll"

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
French Security Incident Response Team : "Msdds.dll" Shinerweb 08-17-2005
Posted by =?Utf-8?B?U2hpbmVyd2Vi?= on August 17, 2005, 4:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I'm surprised to read this tonight:
First I have heard of it, and makes me wonder if there is any truth to it:

http://www.frsirt.com/english/advisories/2005/1450

FrSIRT Advisory : FrSIRT/ADV-2005-1450
CVE Reference : GENERIC-MAP-NOMATCH
Rated as : Critical
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-08-17

* Technical Description *

A critical vulnerability was identified in Microsoft Internet Explorer,
which could be exploited by remote attackers to execute arbitrary commands.
This issue is due to a memory corruption error when instantiating the
"Msdds.dll" object as an ActiveX control, which could be exploited by an
attacker to take complete control of an affected system via a specially
crafted Web page.


Posted by John McGaw on August 18, 2005, 10:51 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Shinerweb wrote:
> I'm surprised to read this tonight:
> First I have heard of it, and makes me wonder if there is any truth to it:
>
> http://www.frsirt.com/english/advisories/2005/1450
>
> FrSIRT Advisory : FrSIRT/ADV-2005-1450
> CVE Reference : GENERIC-MAP-NOMATCH
> Rated as : Critical
> Remotely Exploitable : Yes
> Locally Exploitable : Yes
> Release Date : 2005-08-17
>
> * Technical Description *
>
> A critical vulnerability was identified in Microsoft Internet Explorer,
> which could be exploited by remote attackers to execute arbitrary commands.
> This issue is due to a memory corruption error when instantiating the
> "Msdds.dll" object as an ActiveX control, which could be exploited by an
> attacker to take complete control of an affected system via a specially
> crafted Web page.
>

In the same vein:

http://news.zdnet.com/2100-1009_22-5837611.html?tag=zdfd.newsfeed

The original French report says that the file is installed with Visual
Studio. To which I can add that the file in question seems to be
installed with the ubiquitous Office 2003 (possibly other versions too)
which means that if it is a hole it is a big one.

John McGaw
http://johnmcgaw.com
[Knoxville, TN, USA]

Posted by =?Utf-8?B?U2hpbmVyd2Vi?= on August 19, 2005, 6:23 am
If you were  Registered and logged in, you could reply and use other advanced thread options
This was released late yesterday...

Microsoft Security Advisory (906267)
A COM Object (Msdds.dll) Could Cause Internet Explorer to Unexpectedly Exit
Published: August 18, 2005

http://www.microsoft.com/technet/security/advisory/906267.mspx

Someone needs to have words with FrSirt and thank them for their valuable
efforts in helping those who create the exploits if indeed it turns out to be
one. People who release potential exploits code before prevention is around
should be treated with the same contempt as we have for those who exploit !!!
--
--
http://www.yaps4u.net
http://www.cwic-solutions.co.uk


"Shinerweb" wrote:

> I'm surprised to read this tonight:
> First I have heard of it, and makes me wonder if there is any truth to it:
>
> http://www.frsirt.com/english/advisories/2005/1450
>
> FrSIRT Advisory : FrSIRT/ADV-2005-1450
> CVE Reference : GENERIC-MAP-NOMATCH
> Rated as : Critical
> Remotely Exploitable : Yes
> Locally Exploitable : Yes
> Release Date : 2005-08-17
>
> * Technical Description *
>
> A critical vulnerability was identified in Microsoft Internet Explorer,
> which could be exploited by remote attackers to execute arbitrary commands.
> This issue is due to a memory corruption error when instantiating the
> "Msdds.dll" object as an ActiveX control, which could be exploited by an
> attacker to take complete control of an affected system via a specially
> crafted Web page.
>

Similar ThreadsPosted
Good source of information on incident handling/response? October 13, 2005, 10:49 am
The Microsoft Security Response Center (MSRC) June 4, 2007, 5:47 pm
Product Support Services - SEPTEMBER 2005 MICROSOFT SECURITY RESPONSE CENTER BULLETIN RELEASE - REVISED September 9, 2005, 5:07 pm
Re: Submit questions to Microsoft's team online... May 27, 2005, 7:15 am
gpmonitor in french? July 12, 2005, 11:08 am
question about previous response June 28, 2006, 10:44 am
Rent direct from owners of French gites June 21, 2006, 6:51 am
The Phishing Incident Reporting and Termination Squad is Looking For a Few Good Men and Women March 27, 2006, 10:39 pm
AD 2003 Password Complexity and French Keyboard drivers May 16, 2007, 12:43 pm
Security Breaches Pandemic - Deloitte Touche 2006 Global Security Survey June 27, 2006, 2:10 am

The site map in XML format XML site map

Contact Us | Privacy Policy