Microsoft offers work-around for IE vulnerability
Flaw can cause browser to crash
IDG News Service - Microsoft Corp. has released software that can be used to mitigate a critical vulnerability in Internet Explorer that was first reported last week.
The bug, which concerns the way Internet Explorer handles ActiveX components, can cause the browser to crash and could be used by an attacker to run unauthorized software on the user's machine, Microsoft said.
Yesterday, Microsoft released software that in the registry disables a file called Javaprxy.dll, which is used to run these components in Internet Explorer. This file is used by the Microsoft Java Virtual Machine, the company said.
Microsoft has not yet decided whether it will release a software patch that would fix the underlying problem, a spokeswoman said. "The work-around that they've offered here doesn't fix the underlying vulnerability, but it removes the functionality," she said.
Danish security company Secunia gave the vulnerability its most serious rating, calling it "extremely critical."
The Austrian security researchers who discovered the flaw expect Microsoft eventually to issue a full-blown patch.
"Right now, it's not that dangerous," said Martin Eisner, chief technical officer at security consulting company SEC Consult Unternehmensberatung GmbH. "But of course within a couple of weeks there will be somebody who has a little bit more time than we have and there will be an exploit then," he said in an interview last week.
Microsoft is unaware of any software that has exploited the bug, the spokeswoman said.
Microsoft has issued a security advisory that provides more details on the bug and lists other possible work-arounds to the problem.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Enterprise Java Applications on VMware: Unix to Linux Migration Guide
- This guide focuses on key considerations for IT Architects who are in the process of migrating Java applications from UNIX to Linux as...
- Desktop Modernization eBook
- This eBook looks at the challenges involved in delivering and managing desktops, today and in the future. Its goal is to demonstrate how...
- Market Landscape Report: Online File Sharing and Collaboration in the Enterprise
- The trend toward "consumerization" marches onward in IT; more and more end-users are choosing their own hardware plaforms and software applications in lieu...
- A Standards-based Mobile Application IdM Architecture
- This white paper explains how an identity management architecture, with the help of both SAML and OAuth, can support the two broad categories-web...
- Microsoft Volume Licensing Comparison - Enterprise
- With this quick-reference document, you can easily compare the available Microsoft Volume Licensing programs for enterprise organizations with 250+ devices, and tailor a... All Enterprise Architecture and SOA White Papers
- Quantifying the Business Value of VMware View - Webcast
- Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price...
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn... All Enterprise Architecture and SOA Webcasts