Content

(MS08-069) Microsoft MSXML Nested Tag Vulnerability (955218)

Type
Logic error
Impact of exploitation
Remote Code Execution
User Interaction
user interaction is needed
Attack Vector
Website or e-mail with malicious content
Rating
Medium
CVE reference
CVE-2007-0099,
Vendor Status
Responded and patched
Vulnerable systems
Xml Core Services  3.0,
Summary
A vulnerability exists in Microsoft XML Core Services which may allow for remote code execution.

Tab Navigation

Description

A vulnerability exists in Microsoft XML Core Services which may allow for remote code execution. The flaw is specific to how MSXML handles nested tags. Remote code execution could be achieved if a user is lured into browsing a website, or reads an HTML-formatted email, which contains specially crafted content.

McAfee Product Mitigation & Recommendations

Recommendations

Download and install the patch available from Microsoft(955218): http://www.microsoft.com/technet/security/Bulletin/MS08-069.mspx

McAfee Product Mitigation

McAfee Foundstone
Signature:
(MS08-069) Microsoft MSXML Nested Tag Vulnerability (955218)
Signature identifier:
6217
Release date:
11/11/2008
McAfee Host IPS
Signature:
Generic Buffer Overflow Protection
Signature identifier:
428
Release date:
8/24/2000
First released in:
2.0
McAfee VirusScan Enterprise 8.0i (VSE8.0i) / Managed Virus Scan (MVS) Buffer Overflow Protection
Signature:
Buffer Overflow Protection
Release date:
8/30/2004
First released in:
Build 131
McAfee VirusScan Enterprise 8.5i (VSE8.5i) /Total Protection for Small Business (ToPS SB) Buffer Overflow Protection
Signature:
Buffer Overflow Protection
Release date:
11/29/2006
First released in:
Build 354

Additional Resources

Microsoft Security Bulletin: Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218)

http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx

All Information

Timeline -

11/11/2008

Vendor has provided a patch.

Description -

A vulnerability exists in Microsoft XML Core Services which may allow for remote code execution. The flaw is specific to how MSXML handles nested tags. Remote code execution could be achieved if a user is lured into browsing a website, or reads an HTML-formatted email, which contains specially crafted content.

McAfee Product Mitigation & Recommendations

Recommendations -

Download and install the patch available from Microsoft(955218): http://www.microsoft.com/technet/security/Bulletin/MS08-069.mspx

McAfee Product Mitigation

McAfee Foundstone
Signature:
(MS08-069) Microsoft MSXML Nested Tag Vulnerability (955218)
Signature identifier:
6217
Release date:
11/11/2008
McAfee Host IPS
Signature:
Generic Buffer Overflow Protection
Signature identifier:
428
Release date:
8/24/2000
First released in:
2.0
McAfee VirusScan Enterprise 8.0i (VSE8.0i) / Managed Virus Scan (MVS) Buffer Overflow Protection
Signature:
Buffer Overflow Protection
Release date:
8/30/2004
First released in:
Build 131
McAfee VirusScan Enterprise 8.5i (VSE8.5i) /Total Protection for Small Business (ToPS SB) Buffer Overflow Protection
Signature:
Buffer Overflow Protection
Release date:
11/29/2006
First released in:
Build 354

Additional Resources

Additional Resources -

Microsoft Security Bulletin: Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218)

http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx