Last week, Raff held a "treasure hunt" on his site, where he had hidden the exploit code. He declared "George the Greek" the contest winner in conjunction with the publication of details about the vulnerability.
According to Raff, an attacker can add a maliciously crafted link to any Web page that accepts user generated content that, under certain circumstances, lets the attacker take control of the user's machine when he or she tries to print the page.
When it prints a page, Internet Explorer invokes a local resource script to generate any of the HTML to be printed. "This HTML consists of the following elements: Header, webpage body, footer, and if enabled, also the table of links in the Web page," Raff explains.
Because the script does not validate the URL, an attacker can inject a script that will be executed when the HTML to be printed is generated.
Users of Internet Explorer 7.0 and 8.0b on fully patched Windows XP systems are vulnerable. Users of Windows Vista with User Account Control (UAC) enabled may only be subject to information leakage. Earlier versions of Internet Explorer may also be affected.
Raff said that he alerted Microsoft to the problem on Tuesday and that the company is planning a fix. In the meantime, he advises not using the "Print Table of Links" feature when printing Web pages.
Stay connected and informed by visiting our Enterprise IT Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government, Retail and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.