SCF Advanced Search

  • Total Members: 13889
  • Latest: loutlos
  • Total Posts: 40176
  • Total Topics: 14281
  • Online Today: 699
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)

Author Topic: Vulnerability in Microsoft XML Core Services Opens Door to Attackers  (Read 1744 times)

0 Members and 1 Guest are viewing this topic.


  • SCF VIP Member
  • *****
  • Posts: 776
  • KARMA: 117
  • Gender: Male
  • Pez

Vulnerability in Microsoft XML Core Services Opens Door to Attackers

Microsoft has issued a security advisory that describes a vulnerability in its XML module. McAfee has also observed that the vulnerability is being actively exploited in the wild. The vulnerability exists when the function “msxml3!_dispatchImpl::InvokeHelper” in Microsoft’s XML attempts to access an object in memory that has not been initialized, allowing attacker to execute arbitrary code.

Metasploit has released an exploit module for this vulnerability. We have modified the Metasploit-generated HTML exploit to locate the vulnerability and observed the crash in the msxml module in Internet Explorer. The following code crashes IE.

Larger Picture

Windbg shows Internet Explorer crash

Investigating the crash reveals that the flaw exists in the function “msxml3!_dispatchImpl::InvokeHelper,” which attempts to access an uninitialized local variable as shown in the following image.

Larger Picture

The vulnerable function

This flaw allows an attacker to control the execution of the program and transfer the control to the malicious shellcode.

Larger Picture

Execution transferred to the shellcode

After gaining control, the malicious process decrypts the shellcode and downloads a malicious file from a remote server.

Larger Picture

Decrypting the URL

We have also observed that the attack is carried out by injecting the malicious URL through an iframe. We advise caution while opening unsolicited emails and unknown links. McAfee detects these exploits as “Exploit-CVE-2012-1889.” However, we strongly recommend installing the Microsoft patch to stay protected.

Thanks to my colleagues Varadharajan Krishnasamy and Sujit Ghosal for their valuable contributions.

Orginal article: Monday, June 25, 2012 at 3:11pm by Abhijit Mohanta
Their is two easy way to configure a system!
Every thing open and every thing closed.
Every thing else is more or less complex.

Start Turfing !,8405.msg21475.html#msg21475

Samker's Computer Forum -


With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters)

Enter your email address to receive daily email with ' - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising