MS.IE.OnBeforeUnload.Browser.Entrapment

Last Updated DateNov 10, 2009
Release DateOct 10, 2007
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a URL spoofing vulnerability in Microsoft Internet Explorer 7.

The vulnerability is caused by an error when the vulnerable software handles document.open() call. It allows a remote attacker to prevent users from leaving a site, spoof the address or launch phishing attack.
Affected ProductsMicrosoft Internet Explorer 7.0
Recommended ActionsApply patch, available from the website:
http://www.microsoft.com/technet/security/Bulletin/ms07-057.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3826
Microsoft Bulletin IDMS07-057   http://www.microsoft.com/technet/security/Bulletin/MS07-057.mspx
Reference/shttp://www.securityfocus.com/bid/24911 (BugTraq)
Reference: VID-15058