Jump to content
Nytro

XMLCoreServices Vulnerability Analysis

Recommended Posts

Posted

XMLCoreServices Vulnerability Analysis

Authored by Minsu Kim

This document is an analysis of the XMLCoreServices vulnerability as noted in CVE-2012-1889.

1. Executive Summary

Recently, the malicious web pages exploiting XMLCoreServices vulnerability are frequently

observed, and since Microsoft have released just a temporary fix for this vulnerability, many

Internet Explorer users are exposed to this security threat. This document provides detailed

analysis of XMLCoreServices (CVE-2012-1889) vulnerability.

This vulnerability can be exploited by abusing uninitialized memory section of Microsoft

Core Services 3.0, 4.0, 5.0 and 6.0, and ultimately executes malicious code injected by the

attacker. This vulnerability can be temporarily removed by Fix It

(Microsoft Security Advisory: Vulnerability in Microsoft XML Core Services could allow remote code execution), which disables XML Core Services, however

Microsoft should release official patch to this vulnerability as soon as possible.

This vulnerability has been analyzed on the machine with Windows XP SP2, Internet

Explorer 6, and Microsoft Core Services 3.0. The vulnerability exists in msxml3.dll, which

provides Core Services. The structure of memory where the exploitation of the vulnerability

takes place is shown in Figure 1 below

Download:

http://packetstormsecurity.org/files/download/114977/CSRC-12-03-006.pdf

Sursa: XMLCoreServices Vulnerability Analysis ? Packet Storm

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...