HTTP: Internet Explorer MHT Redirect

This signature detects attempts to bypass Internet Explorer's security zones. A remote user can create a page in the Internet security zone that contains an IFRAME that uses MhtRedirParsesLocalFile to parse a local file. Using a URL of the format "mhtml:url!original_url", IE attempts to download the "original_url".

Extended Description

A vulnerability has been in sub-frames in Microsoft Internet Explorer. Because of this, an attacker may be able to violate cross-domain policy. This could permit script code to access properties of other domains or execute in the context of the Local Zone. Exploitation of this issue in combination with other vulnerabilities could allow for execution of a malicious executable on a vulnerable system.

Affected Products

Microsoft internet_explorer

Short Name
HTTP:STC:IE:IE-MHT-REDIRECT
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2003-1026 Explorer Internet MHT Redirect bid:9109
Release Date
09/01/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Microsoft

CVSS Score

9.3

Found a potential security threat?