Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Microsoft Internet Explorer TIF Folder Vulnerability (MS06-072)

Subscribe

Check Point Reference: CPAI-2007-002
Date Published:
Severity:
Last Updated:
Source: Microsoft Security Bulletin MS06-072
Industry Reference(s): CVE-2006-5578
Protection Provided by: VPN-1
  • NGX R62
  • NGX R61
  • NGX R60
  • NG with Application Intelligence R55W
  • NG with Application Intelligence R55
  • NG with Application Intelligence R54
VSX
  • NGX
InterSpect
  • NGX
  • 2.0 and 1.x
Who is Vulnerable?
Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4
Microsoft Internet Explorer 6 for Windows XP SP2
Microsoft Internet Explorer 6 for Windows XP Professional x64 Edition
Microsoft Internet Explorer 6 for Windows Server 2003
Microsoft Internet Explorer 6 for Windows Server 2003 SP1
Microsoft Internet Explorer 6 for Windows Server 2003 (Itanium)
Microsoft Internet Explorer 6 for Windows Server 2003 with SP1 (Itanium)
Microsoft Internet Explorer 6 for Windows Server 2003 x64 Edition
Vulnerability Description
An information disclosure vulnerability has been identified in Microsoft Internet Explorer. The Temporary Internet Files (TIF) folder contains the cache of the Internet Explorer, enabling faster web browsing and offline browsing. The vulnerability allows remote attackers to retrieve files from the Temporary Internet Files (TIF) folder of an affected system.
Update/Patch Available
Apply patches:
Microsoft Security Bulletin MS06-072
Vulnerability Details
The vulnerability is due to an error in Internet Explorer when handling certain drag and drop operations. A remote attacker may exploit this flaw by convincing a user to view a malicious web page that allows information disclosure when viewed. Successful exploitation could allow an unauthorized user to retrieve files from the TIF folder on a target system.

Protection Overview
The Update enables the Header Rejection protection to detect and block the vulnerability based on pre-defined header names.

In order for the protection to be activated, update your VPN-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
The Update released on January 9, 2007 includes the following protections:
 
Microsoft Internet Explorer Memory Corruption Vulnerability (MS06-072) - CPAI-2007-001
Microsoft Internet Explorer TIF Folder Vulnerability (MS06-072) - CPAI-2007-002
Microsoft Outlook Express Windows Address Book Vulnerability (MS06-076) - CPAI-2007-003
Microsoft Windows Media Player Code Execution Vulnerabilities (MS06-078) - CPAI-2007-004
Malformed IMAP Commands Vulnerabilities (SBP-2007-01)
Blocking Syslog-Related Vulnerabilities (SBP-2007-02)

VPN-1 NGX R62

How Can I Protect My Network?
1. In the SmartDefense tab, click Web Intelligence > HTTP Protocol Inspection > Header Rejection.
2. In the Header Rejection configuration pane, under Header Rejection Settings > Mode, check Active.



3. Enable the following pattern:

TIF Folder Vulnerability (MS06-072)

4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Header Rejection
Attack Information: TIF Folder Vulnerability (MS06-072)

VPN-1 NGX R61, R60 & VPN-1 NG with Application Intelligence R55W

How Can I Protect My Network?
1. In the Web Intelligence tree, click HTTP Protocol Inspection > Header Rejection.
2. Enable the following pattern:

TIF Folder Vulnerability (MS06-072)

3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Header Rejection
Attack Information: TIF Folder Vulnerability (MS06-072)

VPN-1 NG with Application Intelligence R55/R54

How Can I Protect My Network?
1. In the SmartDefense tree, click Application Intelligence > Web > HTTP Protocol Inspection and enable Peer to Peer.
2. Enable the following pattern:

TIF Folder Vulnerability (MS06-072)

3. Install security policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Header Rejection
Attack Information: TIF Folder Vulnerability (MS06-072)

VPN-1 VSX NGX

How Can I Protect My Network?
1. In the SmartDefense tree, click Application Intelligence > Web > HTTP Protocol Inspection and enable Peer to Peer.
2. Enable the following pattern:

TIF Folder Vulnerability (MS06-072)

3. Install security policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Header Rejection
Attack Information: TIF Folder Vulnerability (MS06-072)

InterSpect NGX

How Can I Protect My Network?
1. In the left pane, select Profiles > Default Protection and select the Web Intelligence page of the profile.
2. In the Web Intelligence tree, click HTTP Protocol Inspection > Header Rejection.
3. Enable the following pattern:

TIF Folder Vulnerability (MS06-072)

4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Header Rejection
Attack Information: TIF Folder Vulnerability (MS06-072)

InterSpect 2.0

How Can I Protect My Network?
1. In the SmartDefense tree, click Application Intelligence > Web > HTTP Protocol Inspection  > Peer to Peer.
2. Enable the following pattern:

TIF Folder Vulnerability (MS06-072)

3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Header Rejection
Attack Information: TIF Folder Vulnerability (MS06-072)