Summary:
A LoadLibrary / LoadLibraryEx weakness makes SSL on Internet Explorer very
vulnerable to a ?DLL proxy? attack. If exploited, unencrypted data can be
intercepted before Internet Explorer (IE) uses the SSL module to encrypt the
data. Therefore, confidential information such as bank accounts and
passwords could be stolen. Many applications are vulnerable to ?DLL proxy?
attack with different ramifications.
Vendor Status: Microsoft was informed of this weakness in December 2003. As of February 5, 2004, Microsoft has not provided any indication that they intend to provide any remedies for the affected Windows configurations.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html