Microsoft investigating reports of new IE hole
Security experts this week warned that an exploit is circulating on the Internet
November 4, 2004 12:00 PM ETIDG News Service -
Microsoft Corp. is investigating reports of a serious security flaw in Internet Explorer but has not yet seen malicious code that exploits the reported vulnerability.
Security experts earlier this week warned that code exploiting a newly discovered security hole in Internet Explorer is circulating on the Internet. The code exploits a buffer overflow vulnerability in Internet Explorer 6 and has been confirmed on PCs running Windows XP with Service Pack 1 and Windows 2000, according to Danish security company Secunia.
The U.S. Computer Emergency Readiness Team (CERT) issued an alert similar to the Secunia advisory. CERT warns that in addition to the Web browser, applications such as e-mail clients that rely on browser controls may also be vulnerable. Attackers could gain complete control of a victim's computer by exploiting the flaw, according to Secunia and CERT.
Microsoft is investigating the possible vulnerability, the company said in a statement. However, while Secunia and CERT raise alarm over code exploiting the vulnerability being publicly available, Microsoft said it has not seen that yet. "We have not been made aware of any active exploits of the reported vulnerabilities or customer impact at this time, but we are aggressively investigating the public reports," the company said.
The flaw lies in the way Internet Explorer handles the SRC and NAME attributes of the "frame" and "iframe" HTML elements, according to the CERT alert. A user could be attacked via a Web page containing malicious code or an HTML e-mail message.
There is no patch for this flaw, but computers running Windows XP Service Pack 2 appear to be protected, according to Secunia and CERT.
Upon completing its investigation, Microsoft said it will take the appropriate action to protect Windows users. This may include providing a fix through its monthly patch release process or an out-of-cycle security update, the company said.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Viruses
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Share our Strength
Download Now
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Top 10 Things to Know about Data Protection
Download Now
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Ponemon Study: The Business Risk of a Lost Laptop
Download Now
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Airport Insecurity: The Case of Lost Laptops
Download Now
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
