iEntry 10th Anniversary RSS Newsletter Advertising
Join the WebProWorld Forum!
Text: Decrease Font Size Increase Font Size | Print Print Article | Share: Delicious Digg StumbleUpon Post to Twitter Post to Facebook
CommentMonday, January 10, 2005

New IE Flaws Get Extremely Critical Rating

Three new security vulnerabilities have been found in Internet Explorer 6, they could allow hackers to execute spyware and dialers.

The new security issues, discovered by Security Firm Secunia, even affect computers running Windows XP, even if Microsoft's Service Pack 2 has been used.

Ployer.com says, "Vulnerabilities in Secunia Advisory include - Insufficient validation of drag and drop task from the "Internet" zone to local resources. When this is not checked properly by IE a malicious website can plant arbitrary HTML documents on a user's system. Vulnerability two relates to IE's HTML help control; a specially crafted help (.hhk) file can execute malicious code ; this vulnerability can by-pass the "Local Computer" zone and lock down security features in SP2. Vulnerability three relates to a bug in the way IE handles the "Related Topics" command in an embedded HTML Help control, this can be exploited to allow the execution of malicious code."

Secunia has recommended that IE users disable Active X support to prevent a problem from occurring, until Microsoft has a patch for the problem.

Jeremy Muncy is a staff writer for WebProNews.com

About the author:
Jeremy Muncy has been a part of the WebProNews team and the iEntry Network since 2003. Follow him on Twitter @jmuncy.

Publish A Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
4 + 3 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.
SEARCH












Subscribe to WebProNews


Send me relevant info