Home>News Center>World
             
     

    'Extremely critical' flaw threatens IE users
    (Agencies)
    Updated: 2005-01-12 08:04

    Security experts are warning of a new and highly critical security flaw in Microsoft Internet Explorer, when running under Windows XP SP2.

    Simply visiting a malicious Web site could leave a user's computer vulnerable to malicious code.

    The basic flaw has been known about for two months, but security experts originally thought it would be difficult to exploit. However, after further study, security firm Secunia now says the bug represents a greater danger than previously believed.

    Secunia now rates the vulnerability as "extremely critical."

    Three Problems

    In an alert posted on its Web site, Secunia lists three problems in IE that, in combination, create the vulnerability:

    "Insufficient validation of drag and drop events from the Internet zone to local resources for valid images or media files with embedded HTML code;

    "A security site/zone restriction error, where an embedded HTML Help control on e.g. a malicious web site references a specially crafted index (.hhk) file, can execute local HTML documents or inject arbitrary script code in context of a previous loaded document using a malicious javascript URI handler;

    "A security site/zone restriction error in the handling of the Related Topics command in an embedded HTML Help control can be exploited by e.g. a malicious website to execute arbitrary script code in the context of arbitrary sites or zones."

    The exploit bypasses a key SP2 security feature, Zone Lock Down, which is designed to prevent an attacker from remotely executing script on a local system.

    Safety Measures

    The vulnerability was identified initially by security group Greyhats, which warned of the bug late last month.

    Microsoft is recommending that users turn off the "Drag and drop or copy and paste files" option in Internet Explorer and set security levels to high for the Internet zone.

    Security experts note that the problem does not affect other browsers.

    Secunia has constructed a test, available on the firm's Web site, that users can run to determine whether their systems are affected by this issue.

    Microsoft releases Windows security fixes

    Microsoft Corp. released two security fixes Tuesday that carry its most severe threat rating, including one that applies even to computers that have downloaded the company's massive security update for the Windows XP operating system.

    Both flaws affect versions of the company's dominant operating system going back to Windows 98, and both could allow an attacker to take control of another person's computer.

    One of the flaws also leaves vulnerable users who have downloaded Service Pack 2, a major security upgrade for Windows XP that was released last summer. The security fix came after a series of crippling attacks on Microsoft's technology, which have wreaked havoc on both businesses and computer users.

    Stephen Toulouse, a security program manager at Redmond-based Microsoft, said the company never expected SP 2 to solve all of its security problems.

    "We knew we were going to be providing updates for SP2," he said. "The goal was always around reducing the number of critical updates."

    The flaw that affects SP2 takes advantage of a problem with Internet Explorer that could allow an attacker to gain control of a computer if a user was persuaded to visit a malicious Web site.

    The other flaw could be exploited if a user employs a specially formulated cursor or icon that secretly allowed an attacker to gain control of another person's computer.

    Microsoft also released a third security fix Tuesday with a lesser rating of "important." That vulnerability, which also could allow another person to gain control of a user's computer, affects machines running Windows XP and Windows Server 2003.

    The new security fixes, released as part of Microsoft's regular monthly security updates, come a week after Microsoft said it would begin offering a free program to remove the most dangerous infections from computers. Users who have chosen to automatically receive Microsoft security fixes would begin to receive that removal tool Tuesday, Toulouse said.

    Last week the company also began offering a free program to remove spyware. Spyware can monitor computer users' activities, send annoying pop-up ads and slow computer performance.

    Microsoft also has confirmed plans to sell its own antivirus software, which would compete against programs from McAfee, Symantec and others.



     
      Today's Top News     Top World News
     

    Nation jumps to be world third largest trader

     

       
     

    Hu offers systematic cure to corruption

     

       
     

    Cross-Straits charter flight talks proposed

     

       
     

    Draft law aims to hold back monopolies

     

       
     

    Wintry Beijing tackles heating shortfalls

     

       
     

    'Extremely critical' flaw threatens IE users

     

       
      Allawi admits some areas unsafe to vote
       
      Bush picks ex-prosecutor for homeland post
       
      Sharon phones Abbas in highest contact in years
       
      'Extremely critical' flaw threatens IE users
       
      New case of mad cow confirmed in Canada
       
      Death toll in Australian bushfires rises to 10
       
     
      Go to Another Section  
     
     
      Story Tools  
       
      News Talk  
      Are the Republicans exploiting the memory of 9/11?  
    Advertisement
             
    亚洲AV日韩AV永久无码下载| 最近高清中文字幕无吗免费看 | 国产中文字幕乱人伦在线观看| 日韩一区二区三区无码影院| 在线天堂中文在线资源网| 国产在线拍揄自揄拍无码| 免费无码av片在线观看| 中文字幕精品无码久久久久久3D日动漫| 亚洲AV中文无码字幕色三| 亚洲中文字幕视频国产| 最好看2019高清中文字幕| 亚洲人成无码网WWW| 国产久热精品无码激情| 无码AV片在线观看免费| 国产成人无码区免费内射一片色欲| 欧美日韩中文字幕| 日本妇人成熟免费中文字幕| 无码人妻精品一区二区三区99不卡| 精品日韩亚洲AV无码| 一本加勒比HEZYO无码人妻| 中文字幕精品无码一区二区| 午夜视频在线观看www中文| 最近的中文字幕在线看视频| 亚洲日韩VA无码中文字幕| 久久久久无码精品| 久久久久久国产精品无码下载| 成年午夜无码av片在线观看| 无码国内精品人妻少妇| 人妻无码一区二区三区AV| 熟妇人妻无码中文字幕| 精品无码一区二区三区爱欲 | 无码免费一区二区三区免费播放| 成在人线av无码免费高潮喷水| 亚洲欧美日韩中文字幕二区| 中文字幕乱码免费看电影| 日本在线中文字幕第一视频| 欧美精品丝袜久久久中文字幕| 最近2019年免费中文字幕高清| 国产亚洲美日韩AV中文字幕无码成人| 最近中文字幕完整版免费高清 | 亚洲天堂2017无码中文|