Ads by TechWords

See your link here
Receive the latest technology news and information.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

New bugs found in Outlook, Internet Explorer

The flaws could let an attacker take control of a user's system

April 1, 2005 12:00 PM ET

IDG News Service - Microsoft Corp. is investigating a new set of potentially serious security flaws in Internet Explorer and Outlook reported by security company eEye Digital Security, the software maker said today.
The two flaws in the Web browser and e-mail client could let an attacker take control over a system with minimal action from the user, eEye said in two security alerts posted on its page of upcoming advisories. The company ranks the flaws as "high" risk.
One of the vulnerabilities could let an attacker compromise a user's machine after the user clicks on a Web link, said Marc Maiffret, co-founder and chief hacking officer at eEye. "Nothing that would be normally suspicious to the user," he said.
The flaws affect both Outlook and Outlook Express, Maiffret said.
The vulnerabilities exist in the default installations of the applications on most current versions of Windows, according to Aliso Viejo, Calif.-based eEye. The company said on its Web site that it has informed Microsoft and won't provide further details until Microsoft has provided a patch or security alert.
"We keep all the details private until Microsoft produces a patch. But that is not to say that nobody else has discovered the vulnerability and produced an exploit," Maiffret said. However, eEye hasn't yet seen any attacks that take advantage of the flaws, he said.
Microsoft is investigating the privately reported potential vulnerabilities, a spokeswoman for the software maker said. The company isn't aware of any attempts to exploit the vulnerabilities, she said.
Upon the completion of the investigation, Microsoft will take the appropriate action to protect users. That could be a fix as part of the company's monthly patching cycle, a fix in the next service pack or a special update, the spokeswoman said.
EEye reported the flaws to Microsoft on March 16 and March 29, according to the eEye Web site.
Maiffret said he hopes Microsoft will produce a patch within two months, the industry-standard time for delivering a fix.


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Viruses

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Enterprise Application Delivery: No User Left Behind
Gain the ability to deliver applications to all users, using any device, across any network.  

Gartner: Magic Quadrant for Application Delivery Controllers, 2009
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing...  

Data Protection is not an insurance policy -you cannot buy-back lost data
Find out why you need to maintain access to critical information to run your business and remain competitive.

Chiquita selects Workday's fresh approach to Human Capital Management
A fresh approach to meet IT and HR objectives.  

ITIL in Tough Economic Times
Are you looking for new inspiration to move forward with ITIL in these tough economic times?

The ROI of Software-As-A-Service
A Total Economic Impact™ Analysis Uncovers Long-Term Value In SaaS  

IT Governance Podcast: IT Provider Forecasts $10 Million in Savings
In this podcast, learn how OTS was able to prioritize, then deliver, on the mission-critical demands and, in the process, project $10 million...