Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Preemptive Protection against Microsoft Internet Explorer HTML Object Memory Corruption Vulnerability

Subscribe

Check Point Reference: CPAI-2009-247
Date Published:
Preemptive Since:
Severity:
Last Updated:
Source: Microsoft Security Advisory (977981)
Microsoft Security Bulletin MS09-072
Industry Reference(s): CVE-2009-3672
Protection Provided by: Security Gateway
  • R70
VPN-1
  • NGX R65
VSX
  • NGX R65
InterSpect
  • NGX
Who is Vulnerable?
Internet Explorer 6 SP1 on Microsoft Windows 2000 SP4
Internet Explorer 6 and Internet Explorer 7 on:
Windows XP
Windows Server 2003
Windows Vista
Windows Server 2008
Vulnerability Description
A memory corruption vulnerability has been reported in Microsoft Internet Explorer. A remote attacker could exploit this issue by convincing a user to open a maliciously crafted HTML file with Internet Explorer, which will cause the browser to crash and may allow execution of arbitrary commands.
Update/Patch Available
Apply patches:
Microsoft Security Bulletin MS09-072
Vulnerability Details
The vulnerability is due to the way Internet Explorer accesses an object that has been deleted. To trigger this issue, an attacker may create a malicious web page that will cause Internet Explorer to access exit unexpectedly. Successful exploitation of this vulnerability will crash the browser, and may allow execution of arbitrary code on the vulnerable system.

Protection Overview
This protection detects and blocks HTML pages attempting to exploit this vulnerability. No update is required to address this vulnerability.

Users of the IPS Software Blade in Security Gateway R70, employing the Recommended Protection Profile, are already protected and no additional configuration is needed on their side.

To configure the defense, select your product from the list below and follow the related protection steps.

Security Gateway R70

How Can I Protect My Network?
1. In the IPS tab, click Protections > By Protocol > Web Intelligence > HTTP Client Protections > Microsoft Internet Explorer Vulnerabilities.
2. In the right pane, double-click the Internet Explorer Heap Spray Shell Code Execution (MS06-055 MS06-067) protection.
3. In the Protection Details window, click on Edit. Choose the protection's Action (Override IPS Policy with: Prevent/Detect), and apply Additional Settings.
4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Web Client Enforcement Violation
Attack Information: Internet Explorer heap spray shell code execution (MS06-055 MS06-067)

VPN-1 NGX R65 & VSX NGX R65

How Can I Protect My Network?
1. In the SmartDefense tab, click Web Intelligence > HTTP Client Protections > Microsoft Internet Explorer Vulnerabilities > Block Heap Spray Remote Shell Code Execution.
2. In the configuration pane, under Settings > Mode, check Active.
3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Web Client Enforcement Violation
Attack Information: Heap spary remote shell code execution

InterSpect NGX

How Can I Protect My Network?
1. In the left pane, select Profiles > Default Protection and select the SmartDefense page of the profile.
2. In the SmartDefense tree, click Web Intelligence > HTTP Client Protections > Microsoft Internet Explorer Vulnerabilities and enable Block Heap Spray Remote Shell Code Execution.
3. Install security policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Web Client Enforcement Violation
Attack Information: Heap spary remote shell code execution