久久久无码人妻精品无码_6080YYY午夜理论片中无码_性无码专区_无码人妻品一区二区三区精99

  Home>News Center>World
         
 

'Extremely critical' flaw threatens IE users
(Agencies)
Updated: 2005-01-12 08:04

Security experts are warning of a new and highly critical security flaw in Microsoft Internet Explorer, when running under Windows XP SP2.

Simply visiting a malicious Web site could leave a user's computer vulnerable to malicious code.

The basic flaw has been known about for two months, but security experts originally thought it would be difficult to exploit. However, after further study, security firm Secunia now says the bug represents a greater danger than previously believed.

Secunia now rates the vulnerability as "extremely critical."

Three Problems

In an alert posted on its Web site, Secunia lists three problems in IE that, in combination, create the vulnerability:

"Insufficient validation of drag and drop events from the Internet zone to local resources for valid images or media files with embedded HTML code;

"A security site/zone restriction error, where an embedded HTML Help control on e.g. a malicious web site references a specially crafted index (.hhk) file, can execute local HTML documents or inject arbitrary script code in context of a previous loaded document using a malicious javascript URI handler;

"A security site/zone restriction error in the handling of the Related Topics command in an embedded HTML Help control can be exploited by e.g. a malicious website to execute arbitrary script code in the context of arbitrary sites or zones."

The exploit bypasses a key SP2 security feature, Zone Lock Down, which is designed to prevent an attacker from remotely executing script on a local system.

Safety Measures

The vulnerability was identified initially by security group Greyhats, which warned of the bug late last month.

Microsoft is recommending that users turn off the "Drag and drop or copy and paste files" option in Internet Explorer and set security levels to high for the Internet zone.

Security experts note that the problem does not affect other browsers.

Secunia has constructed a test, available on the firm's Web site, that users can run to determine whether their systems are affected by this issue.

Microsoft releases Windows security fixes

Microsoft Corp. released two security fixes Tuesday that carry its most severe threat rating, including one that applies even to computers that have downloaded the company's massive security update for the Windows XP operating system.

Both flaws affect versions of the company's dominant operating system going back to Windows 98, and both could allow an attacker to take control of another person's computer.

One of the flaws also leaves vulnerable users who have downloaded Service Pack 2, a major security upgrade for Windows XP that was released last summer. The security fix came after a series of crippling attacks on Microsoft's technology, which have wreaked havoc on both businesses and computer users.

Stephen Toulouse, a security program manager at Redmond-based Microsoft, said the company never expected SP 2 to solve all of its security problems.

"We knew we were going to be providing updates for SP2," he said. "The goal was always around reducing the number of critical updates."

The flaw that affects SP2 takes advantage of a problem with Internet Explorer that could allow an attacker to gain control of a computer if a user was persuaded to visit a malicious Web site.

The other flaw could be exploited if a user employs a specially formulated cursor or icon that secretly allowed an attacker to gain control of another person's computer.

Microsoft also released a third security fix Tuesday with a lesser rating of "important." That vulnerability, which also could allow another person to gain control of a user's computer, affects machines running Windows XP and Windows Server 2003.

The new security fixes, released as part of Microsoft's regular monthly security updates, come a week after Microsoft said it would begin offering a free program to remove the most dangerous infections from computers. Users who have chosen to automatically receive Microsoft security fixes would begin to receive that removal tool Tuesday, Toulouse said.

Last week the company also began offering a free program to remove spyware. Spyware can monitor computer users' activities, send annoying pop-up ads and slow computer performance.

Microsoft also has confirmed plans to sell its own antivirus software, which would compete against programs from McAfee, Symantec and others.



 
  Today's Top News     Top World News
 

Nation jumps to be world third largest trader

 

   
 

Hu offers systematic cure to corruption

 

   
 

Cross-Straits charter flight talks proposed

 

   
 

Draft law aims to hold back monopolies

 

   
 

Wintry Beijing tackles heating shortfalls

 

   
 

'Extremely critical' flaw threatens IE users

 

   
  Allawi admits some areas unsafe to vote
   
  Bush picks ex-prosecutor for homeland post
   
  Sharon phones Abbas in highest contact in years
   
  'Extremely critical' flaw threatens IE users
   
  New case of mad cow confirmed in Canada
   
  Death toll in Australian bushfires rises to 10
   
 
  Go to Another Section  
 
 
  Story Tools  
   
  News Talk  
  Are the Republicans exploiting the memory of 9/11?  
Advertisement
         
久久久无码人妻精品无码_6080YYY午夜理论片中无码_性无码专区_无码人妻品一区二区三区精99

    欧美男女爱爱视频| 国产探花在线观看视频| 欧美伦理片在线观看| 天堂av免费看| 久久久久久久久久久福利| www.超碰97.com| 亚洲 欧美 日韩 国产综合 在线| 日本在线播放一区二区| 97在线国产视频| www.亚洲自拍| 国产极品美女高潮无套久久久| 国产精品12p| 成人性生生活性生交12| 夜夜添无码一区二区三区| 亚洲欧美手机在线| 日韩手机在线观看视频| 青青青青在线视频| 青青草原播放器| 亚洲黄色a v| 无码人妻精品一区二区三区在线| 警花观音坐莲激情销魂小说| 中文字幕av不卡在线| 男人揉女人奶房视频60分| 免费的一级黄色片| 亚洲欧美天堂在线| 蜜桃免费在线视频| 37pao成人国产永久免费视频| 国产成人永久免费视频| 日本丰满大乳奶| 国产精品区在线| 男人天堂手机在线视频| 一本—道久久a久久精品蜜桃| 国产一线二线三线在线观看| 亚洲熟妇av一区二区三区漫画| 伊人网在线免费| 交换做爰国语对白| 激情黄色小视频| 天天色综合天天色| 毛片毛片毛片毛片毛片毛片毛片毛片毛片 | 国产精品三级一区二区| 欧美h视频在线观看| 亚洲一区二区福利视频| 91制片厂毛片| 我看黄色一级片| 丰满少妇在线观看| 日本va中文字幕| 久久久久久久片| 一本久道中文无码字幕av| 久久精品香蕉视频| 一本久道中文无码字幕av| 黄色片视频在线免费观看| 国产精品无码av在线播放 | 黄色免费网址大全| 另类小说第一页| 国产精品一区二区羞羞答答| 九九热在线免费| 中文字幕在线综合| 91丨九色丨蝌蚪| 国产精品igao网网址不卡| 婷婷视频在线播放| 99久久99久久精品| 欧美国产日韩激情| 黄网站欧美内射| 日韩久久一级片| 亚洲最大综合网| 久久6免费视频| 18视频在线观看娇喘| 97碰在线视频| 亚洲国产精品久久久久婷蜜芽| 黄色片视频在线免费观看| 精品一卡二卡三卡| 亚洲欧美日本一区二区三区| 国产精品igao网网址不卡| 人妻互换免费中文字幕| 熟女少妇在线视频播放| 亚洲精品一二三四五区| 中文字幕 欧美日韩| 玖玖精品在线视频| 男人添女人下面高潮视频| 亚洲精品一二三四五区| 亚洲成人手机在线观看| 国产xxxx振车| 992kp快乐看片永久免费网址| 亚洲天堂网站在线| 人人妻人人做人人爽| 三年中国国语在线播放免费| 亚洲色图欧美自拍| 被灌满精子的波多野结衣| 亚洲免费av一区二区三区| 黄色一级片免费播放| 日本丰满少妇xxxx| 国产精品区在线| 日本人妻伦在线中文字幕| 欧美视频免费播放| 日韩精品视频网址| 啊啊啊国产视频| 久久国产午夜精品理论片最新版本| 免费在线观看视频a| 国产裸体免费无遮挡| 性欧美18一19内谢| www.四虎成人| 中文字幕av久久| 中文字幕无码不卡免费视频| 99re99热| 国产天堂在线播放| 欧美 国产 精品| 激情五月婷婷久久| 欧美精品卡一卡二| 婷婷激情小说网| 国产精品欧美激情在线观看| 91香蕉视频网址| 国产精品少妇在线视频| 国产又粗又长又爽视频| 天天干天天爽天天射| 国产一级爱c视频| 91日韩精品视频| 国产欧美高清在线| 国产 欧美 日韩 一区| 日本人69视频| 日韩欧美精品在线观看视频| 三级在线免费观看| 少妇网站在线观看| 大陆极品少妇内射aaaaa| 一区二区三区一级片| 网站一区二区三区| 欧美日韩精品在线一区二区 | 免费看啪啪网站| 国产视频在线视频| 久草热视频在线观看| 国产激情在线看| 五月天婷婷在线观看视频| 亚洲一二三区av| 精品中文字幕av| 成人性免费视频| 992tv快乐视频| 91免费国产精品| 日韩高清在线一区二区| 日本人视频jizz页码69| 免费毛片小视频| 一女被多男玩喷潮视频| 日本免费a视频| 男女爱爱视频网站| 91小视频在线播放| xxww在线观看| 婷婷六月天在线| www.超碰com| 日韩在线第三页| 成年人黄色片视频| 天天综合网久久| 少妇性饥渴无码a区免费| 国产传媒久久久| 992tv成人免费观看| 香蕉视频xxxx| 91网址在线观看精品| www.欧美激情.com| 亚洲av无日韩毛片久久| 激情五月俺来也| 国产喷水theporn| 另类小说色综合| 99热一区二区| 亚洲天堂网2018| 亚洲涩涩在线观看| 亚洲一二三不卡| 中文字幕第22页| 在线免费观看av网| 天堂v在线视频| 国风产精品一区二区| 激情五月六月婷婷| 色欲色香天天天综合网www| 久久99中文字幕| 无码精品a∨在线观看中文| www.玖玖玖| 日本www.色| 精品国产乱码久久久久久1区二区| 黄瓜视频免费观看在线观看www| 欧洲xxxxx| 久久99久久久久久| 国产中文字幕在线免费观看| 久久精品.com| 国产视频1区2区3区| 日本黄色播放器| 男人靠女人免费视频网站| 五月天综合婷婷| ijzzijzzij亚洲大全| 成年丰满熟妇午夜免费视频| 福利视频一区二区三区四区| 波多野结衣在线免费观看| 五月六月丁香婷婷| 日本男女交配视频| 国模杨依粉嫩蝴蝶150p| jizz欧美性11| 久久国产精品免费观看| 91成人在线观看喷潮教学| av无码精品一区二区三区| 亚洲女人在线观看| 欧美精品自拍视频| 欧美wwwwwww| 中文字幕日韩精品无码内射| 日韩精品一区二区三区久久| 天堂网在线免费观看|