Content

(MS09-054) Data Stream Header Corruption Vulnerability (974455)

Type
Logic error
Impact of exploitation
Remote Code Execution
User Interaction
user interaction is needed
Attack Vector
Website with malicious content
Rating
High
CVE reference
CVE-2009-1547,
Vendor Status
Responded and patched
Vulnerable systems
Internet Explorer  All Versions,
Summary
A remote code execution vulnerability exists in the way that Internet Explorer processes data stream headers in specific situations

Tab Navigation

Description

A remote code execution vulnerability exists in the way that Internet Explorer processes data stream headers in specific situations. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

McAfee Product Mitigation & Recommendations

Recommendations

The vendor has released a patch to address this issue: http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx

McAfee Product Mitigation

McAfee Foundstone
Signature:
(MS09-054) Data Stream Header Corruption Vulnerability (974455)
Signature identifier:
7194
Release date:
10/13/2009
McAfee Intrushield
Signature:
HTTP: Microsoft Data Stream Header Corruption Vulnerability
Signature identifier:
0x40269F00
Release date:
10/13/2009
First released in:
4.1.59, 5.1.29
McAfee Host IPS
Signature:
Generic Buffer Overflow Protection
Signature identifier:
428
Release date:
8/24/2000
First released in:
2.0
Signature:
(MS09-054) Data Stream Header Corruption Vulnerability (974455)
Signature identifier:
7194
Release date:
10/14/2009
McAfee VirusScan Enterprise 8.0i (VSE8.0i) / Managed Virus Scan (MVS) Buffer Overflow Protection
Signature:
Generic Buffer Overflow Protection
McAfee VirusScan Enterprise 8.5i (VSE8.5i) /Total Protection for Small Business (ToPS SB) Buffer Overflow Protection
Signature:
Generic Buffer Overflow Protection
Signature:
Generic Buffer Overflow Protection
McAfee Anti-Virus protection

Detection for known attack vectors will be provided in 5772 DATs when using gateway products such as SIG, SWG, GS.

Signature:
5772
Release date:
10/14/2009
First released in:
Exploit-CVE2009-1547

Additional Resources

(MS09-054) Data Stream Header Corruption Vulnerability (974455)

http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx

All Information

Timeline -

10/15/2009

A proof of concept has been released.

10/13/2009

Vendor has provided a patch.

Description -

A remote code execution vulnerability exists in the way that Internet Explorer processes data stream headers in specific situations. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

McAfee Product Mitigation & Recommendations

Recommendations -

The vendor has released a patch to address this issue: http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx

McAfee Product Mitigation

McAfee Foundstone
Signature:
(MS09-054) Data Stream Header Corruption Vulnerability (974455)
Signature identifier:
7194
Release date:
10/13/2009
McAfee Intrushield
Signature:
HTTP: Microsoft Data Stream Header Corruption Vulnerability
Signature identifier:
0x40269F00
Release date:
10/13/2009
First released in:
4.1.59, 5.1.29
McAfee Host IPS
Signature:
Generic Buffer Overflow Protection
Signature identifier:
428
Release date:
8/24/2000
First released in:
2.0
Signature:
(MS09-054) Data Stream Header Corruption Vulnerability (974455)
Signature identifier:
7194
Release date:
10/14/2009
McAfee VirusScan Enterprise 8.0i (VSE8.0i) / Managed Virus Scan (MVS) Buffer Overflow Protection
Signature:
Generic Buffer Overflow Protection
McAfee VirusScan Enterprise 8.5i (VSE8.5i) /Total Protection for Small Business (ToPS SB) Buffer Overflow Protection
Signature:
Generic Buffer Overflow Protection
Signature:
Generic Buffer Overflow Protection
McAfee Anti-Virus protection

Detection for known attack vectors will be provided in 5772 DATs when using gateway products such as SIG, SWG, GS.

Signature:
5772
Release date:
10/14/2009
First released in:
Exploit-CVE2009-1547

Additional Resources

Additional Resources -

(MS09-054) Data Stream Header Corruption Vulnerability (974455)

http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx