IE Bugs Now 'Extremely Critical' - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
Software // Enterprise Applications
News
1/10/2005
01:32 PM
50%
50%

IE Bugs Now 'Extremely Critical'

An unpatched, months-old vulnerability in Microsoft's Internet Explorer is now even more dangerous, security firms warn.

An unpatched, months-old vulnerability in Microsoft's Internet Explorer is now even more dangerous, security firms reported Monday.

Danish security vendor Secunia warned that new exploits of an earlier series of vulnerabilities in IE now let hackers compromise Windows computers without any more work than enticing users to malicious Web sites.

In August and then again in October 2004, Secunia broadcast warnings of similar threats to IE, but at the latter date posted proof-of-concept code which required the user to actually drag and drop a file within the browser to be at risk. The exploits now in the wild, said Secunia and the SAN Institute's Internet Storm Center, are automated and require no user action except visiting a hacker-constructed site.

In response, Secunia upped its assessment of the vulnerability to "extremely critical,' its most dire warning.

The three vulnerabilities noted by Secunia affect Internet Explorer 6.x, including the version bundled with Windows XP Service Pack 2 (SP2), the massive update from last October which was touted by Microsoft as a major security upgrade.

SAN Institute's Internet Storm Center confirmed the vulnerabilities, which "will allow remote code execution on a victim's system just by visiting the [malicious] site."

The Center said it had received e-mail with a link to such a site -- users would still have to be drawn to the site -- and noted that "as of now, there is no patch available."

Secunia has posted an online test that users can run to determine if their browser is vulnerable.

Until a patch is available, IE users should consider switching browsers, said Secunia, or disabling the "Drag and Drop or copy and paste files option in Internet Explorer. Microsoft has posted a document on its support site that explains the process.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
Slideshows
Reflections on Tech in 2019
James M. Connolly, Editorial Director, InformationWeek and Network Computing,  12/9/2019
Slideshows
What Digital Transformation Is (And Isn't)
Cynthia Harvey, Freelance Journalist, InformationWeek,  12/4/2019
Commentary
Watch Out for New Barriers to Faster Software Development
Lisa Morgan, Freelance Writer,  12/3/2019
White Papers
Register for InformationWeek Newsletters
Video
Current Issue
The Cloud Gets Ready for the 20's
This IT Trend Report explores how cloud computing is being shaped for the next phase in its maturation. It will help enterprise IT decision makers and business leaders understand some of the key trends reflected emerging cloud concepts and technologies, and in enterprise cloud usage patterns. Get it today!
Slideshows
Flash Poll