On CBS MoneyWatch: How to Get Into Harvard
BNET Business Network:
BNET
TechRepublic
ZDNet

May 30th, 2008

Microsoft issues Safari-to-IE blended threat warning

Posted by Ryan Naraine @ 5:16 pm

Categories: Apple, Arbitrary Code Execution, Browsers, Complex Attacks, Exploit code, Hackers, Microsoft, Patch Watch, Responsible disclosure, Vulnerability research, Windows Vista

Tags: Apple Safari, Microsoft Corp., Microsoft Windows, Web Browsers, Operating Systems, Security, Software, Internet, Ryan Naraine

Microsoft issues Safari-to-Windows blended threat warningMicrosoft has issued a formal security advisory with a confirmation of public warnings that the Safari “carpet bombing” vulnerability presents a remote code execution threat on all supported editions of Windows XP and Windows Vista.

The pre-patch advisory from Redmond follows public pressure from the Google-backed StopBadware.org for Apple to rethink its stance that the Safari issue should be considered a serious security vulnerability.

From the Microsoft advisory:

A combination of the default download location in Safari and how the Windows desktop handles executables creates a blended threat in which files may be downloaded to a user’s machine without prompting, allowing them to be executed.

…An attacker could trick users into visiting a specially crafted Web site that could download content to a user’s machine and execute the content locally using the same permissions as the logged-on user.

 [ SEE: Why Apple must fix Safari 'carpet bombing' flaw immediately ]

According to the advisory, the Windows portion of the blended threat is linked to Internet Explorer (IE 6 and IE 7 on Windows XP and Windows Vista, all service packs included).    Technical details on the combo-threat are being kept under wraps but it is clear that Microsoft has

actual proof of an IE vulnerability can be used in tandem with Nitesh Dhanjani’s Safari bug to launch a malicious executable if a user surfs to a rigged site with Safari.

Officials in the MSRC (Microsoft Security Response Center) held discussions with Apple before releasing the advisory.

[ SEE: Apple under pressure to fix Safari ‘carpet bomb’ flaw ]

As a temporary mitigation, Microsoft recommends that Windows uses restrict the use of Safari as a web browser until an appropriate update is available from Microsoft and/or Apple.

Alternatively, if you must use Safari, you should change the download location of content in Safari to a location other than ‘Desktop’.   This can be done by launching Safari and using the Edit > Preferences and selecting a different location on the local drive for  Save Downloaded Files to: option.

My previous advice stands.  Uninstall Safari and use an alternative browser on Windows.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 54 Talkback(s)
Why in the world would ANYONE use Safari on Windows?
There are plenty of far superior alternatives. What's the point? (Read the rest)
Posted by: butler360 Posted on: 06/25/08 You are currently: a Guest | | Terms of Use
I don't get it  Yagotta B. Kidding | 05/30/08
Windows: .exe = executable  AySz88 | 05/30/08
Confirmation...  Spiritusindomit@... | 06/02/08
RE: Microsoft issues Safari-to-IE blended threat warning  ZachE84 | 05/30/08
M$ issues Safari warning  bfilipiak@... | 06/02/08
Same Situation, Different Day  D-T-Schmitz | 05/30/08
Doesn't that just open a whole other  Pliny the Elder | 05/30/08
Great questions  D-T-Schmitz | 05/31/08
Ergh...  nmcfeters | 06/03/08
ZZZZZZZZZZ...nt  ItsTheBottomLine | 06/02/08
damn right  rebelxhardcore | 06/02/08
Oh the irony...  zkiwi | 05/30/08
Really, really ironic..  silent.griffin | 05/31/08
Don't try and say advertising is the same as an advisory (nt)  zkiwi | 05/31/08
Yep, they're different.  silent.griffin | 06/01/08
Yet they don't advise people...  zkiwi | 06/01/08
Label away...  zkiwi | 06/01/08
The difference between advertising and advisories  Hemlock Stones | 06/02/08
The advisory is a bit specious, but...  bmerc | 06/02/08
Nice word...  zkiwi | 06/02/08
The difference being  tikigawd | 06/02/08
Your'e missing the bit about Microsoft's suggested workaround  zkiwi | 06/02/08
@hemlock  zkiwi | 06/02/08
This is better  rtk | 05/30/08
And...  Qbt | 05/31/08
They way I read it is..  A Grain of Salt | 05/31/08
No extra click required  Ryan NaraineZDNet Moderator | 05/31/08
Well..  ZachE84 | 05/31/08
Firefox has had it's share of problems  nmcfeters | 06/03/08
I would not consider any vulnerability  frgough | 06/02/08
Could you provide some more info?  balaknair | 06/02/08
You misunderstood his post  cslycord@... | 06/02/08
OK, thanks for clarifying  balaknair | 06/03/08
What he means is  tikigawd | 06/02/08
Seems like it (: P)  balaknair | 06/03/08
Would uninstalling IE help?  visoot | 06/04/08
Stupid me!  visoot | 06/05/08
Good points but for the end  nilotpal_c | 05/31/08
IS there any reason why Windows Desktop should be executing files? (nt)  CobraA1 | 06/02/08
You have to think of Windows desktop  alaniane@... | 06/02/08
Safari is a joke anyway  masonwheeler | 06/02/08
I'm sorry but,  CowLauncher | 06/02/08
Spreading FUD?  masonwheeler | 06/02/08
I tried Firefox and went straight back to Safari  labarker | 06/02/08
RE: Microsoft issues Safari-to-IE blended threat warning  support1@... | 06/02/08
64-bit is no panacea. In fact, a MAJOR malware exploit can ONLY be 64-bit!  Joel R | 06/02/08
Well...  Spiritusindomit@... | 06/02/08
huh?  /A\V/ | 06/02/08
And so say all of us.  odubtaig | 06/02/08
That was my thinking  laura.b | 06/03/08
RE: Microsoft issues Safari-to-IE blended threat warning  jerang@... | 06/02/08
RE: Microsoft issues Safari-to-IE blended threat warning  thrasher6900@... | 06/05/08
Don't you mean  laura.b | 06/06/08
Why in the world would ANYONE use Safari on Windows?  butler360 | 06/25/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads