Internet Explorer has a security hole in JavaScript
Summary
In January 2002 the Bulgarian security researcher Georgi Guninski published a hole in Internet Explorer through which JavaScript could read local files and start programs. The cause was an incorrect interpretation of the GetObject() function; the patched IE 6.0 and IE 5.5 SP2 under Windows 2000 were affected. According to Guninski, Microsoft had been informed three weeks earlier and had not responded.
Ideas
- A script function in the browser could access the local file system.
- When the vendor did not respond, the discoverer published the details.
- Even fully patched browsers were affected.
Insights
- Publication after a deadline has passed puts pressure on tardy vendors.
- In early browsers the boundary between web content and the local system was permeable.
Facts
- The hole was discovered in the second week of December 2001.
- Guninski recommended permanently disabling Active Scripting in Internet Explorer.
References
Critique
- The report reproduces Guninski’s account without obtaining a statement from Microsoft.
Recommendations
- Disable active content for untrusted sites when a browser has unpatched holes.
- With known, open browser holes, temporarily use an alternative browser.
Links to the original source and the Web Archive open in a new tab.