J-Security Center

Title: Microsoft IE and OE XML Stylesheets Active Scripting Vulnerability

Severity: HIGH

Description:

A vulnerability exists in the handling of XML stylesheet files in Internet Explorer and Outlook Express. This vulnerability allows script contained in an XML stylesheet to be run on a user's system even if active scripting is disabled in all security zones.

Extensible Markup Language (XML) defines the components of elements on a web page. HTML defines how elements are displayed. Extensible Stylesheet Language (XSL) is a language used to create stylesheets for XML documents. A stylesheet defines how a web document is going to appear containing elements such as color, heading, body text, spacing, size, etc. It is not uncommon for XML markup to be incorporated in an HTML web page.

A website or an email message could contain a link to an XML web document. If the XML document's stylesheet (XSL) contains script (ie.Javascript & VBscript modules), when accessed by the user the script would run even if active scripting has been disabled in all security zones.

Successful exploitation of this vulnerability could lead to complete compromise of the target host.

Affected Products:

  • Microsoft Internet Explorer 5.0
  • Microsoft Internet Explorer 5.0.1
  • Microsoft Internet Explorer 5.0.1 for Windows 2000
  • Microsoft Internet Explorer 5.0.1 for Windows 95
  • Microsoft Internet Explorer 5.0.1 for Windows 98
  • Microsoft Internet Explorer 5.0.1 for Windows NT 4.0
  • Microsoft Internet Explorer 5.5
  • Microsoft Outlook Express 5.5
  • Microsoft Windows 98SE
  • Microsoft Windows ME

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.