Rule:

--
Sid:
2671

--
Summary:
This event is generated when an attempt is made to exploit a known
vulnerability in Microsoft Internet Explorer.

--
Impact:
A successful attack can cause a buffer overflow and present the attacker
with the opportunity to execute code of their choosing on a vulnerable
system.

--
Detailed Information:
An error in the processing of bitmap images exists in Internet Explorer
that can present an attacker with the opportunity to execute code of
their choosing on a vulnerable system.

The error exists due to poor boundary checking in the processing of
bitmap images.

--
Affected Systems:
	Microsoft Windows using Internet Explorer

--
Attack Scenarios:
An attacker would need to supply a malformed bitmap image either in a
web page or possibly via HTML email to a victim host.

--
Ease of Attack:
Simple, exploits exist.

--
False Positives:
None known.

--
False Negatives:
None known.

--
Corrective Action:
Upgrade to the latest non-affected version of the software.

Apply the appropriate vendor supplied patches.

--
Contributors:
Sourcefire Vulnerability Research Team
Matt Watchinski <mwatchinski@sourcefire.com>
Brian Caswell <bmc@sourcefire.com>
Nigel Houghton <nigel.houghton@sourcefire.com>

--
Additional References:

Microsoft:
http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx

--
