Microsoft to fix broken IE security, warns of hole in WS 2000 and kills a Forefront product

Analysis
Apr 21, 20103 mins

After Blackhat demo showed IE's own security creating a giant hole, Microsoft promises a fix in June.

Microsoft says that a hole demonstrated at Blackhat EU last week against IE will be patched in June. The demonstration involves the IE XSS Filter and a new way to attack a hole that was disclosed and patched in January (with patch MS10-002). The company also today advised Windows 2000 Server users of a critical hole in Windows Media Services. On Windows 2000 Server, Windows Media Services is an optional component and not installed by default.

As for the Blackhat hole, which Microsoft calls IE XSS Filter, Microsoft’s David Ross on the MSRC Engineering blog explains:

“This [additional update scheduled in June] will address a SCRIPT tag attack scenario described in the Blackhat EU presentation. This issue manifests when malicious script can “break out” from within a construct that is already within an existing script block.  While the issue identified and addressed in MS10-002 was identified to exist on high-profile web sites, thus far real-world examples of the SCRIPT tag neutering attack scenario have been hard to come by.”

Perhaps examples were hard to come by prior to the Blackhat demo, but what’s so interesting about this hole is that it actually uses one of the IE8’s security features. This is how the Blackhat session, conducted by David Lindsay and Eduardo Vela Nava was billed:

“Internet Explorer 8 has built in cross-site scripting (XSS) detection and prevention filters. We will explore the details of how the filters detect attacks, the neutering method, and discuss the filters’ general strengths and weaknesses. We will demonstrate several ways in which the filters can be abused (not just bypassed) in order to enable XSS on sites that would not otherwise be vulnerable. We will then show how this vulnerability makes most every major website vulnerable to XSS in affected versions of Internet Explorer 8.”

Updated 04/23/10: Microsoft has contacted me and offered me more details, and a few corrections, about the demise of this Forefront security product.

In one more bit of security news, Microsoft has also said that its management product for its endpoint protection products, code-named “Stirling” since dubbed Forefront Protection Suite, Forefront Protection Manager will not be sold as a standalone product (originally reported by the Register). Instead, it will be incorporated as a component of System Center Configuration Manager. A Microsoft spokesperson explains, “We’re providing management tools for Forefront Protection for SharePoint and Exchange, and management of Forefront Endpoint Protection will be done within System Center Configuration Manager”

Forefront Protection Manager was initially part of the mega security suite code-named Stirling and now called Forefront Protection Suite. The beta of Stirling was released a year ago at the RSA conference.

Posted by Julie Bort

Like this post? Check out these others.

  • Data Protection Manager 2010 Protection Best Practices
  • After three years effort, Microsoft’s open source IronRuby stable and available
  • Bigger is better when it comes to mailboxes, Microsoft says
  • Microsoft … oh how you’ve changed! (Not)
  • Understanding How System Center Operations Manager Works
  • Patch Tuesday brings bevy of critical updates
Plus, visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.) All Microsoft Subnet bloggers on Twitter Julie Bort on Twitter

Follow

Follow