ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Flaw lets malicious Web pages attack Windows

Published: 20 Mar 2003 09:21 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A vulnerability in all versions of Windows could allow attackers to use a malicious Web site or HTML email message to trap victims and take control of their PCs, warned Microsoft.

The flaw in the scripting component of the operating system lets attackers run code through the scripting engine as if the program had been executed locally on a PC, allowing them to run their own programs or to take over the system. Microsoft labelled the flaw as critical in its announcement on Wednesday.

While the flaw can be found in every version of Windows -- from Windows 98 to Windows XP -- the potential danger is offset by two factors. First, security measures already in place in email clients are designed to defeat such HTML message attacks. Second, exploiting such flaws through Web pages requires that the person under attack actually visit the malicious site.

"The email vector is only a threat with an older version of Outlook," said Iain Mulholland, security program manager for Microsoft's security response centre. Mulholland added that it would be difficult to create a virus from the flaw. "It's blocked on later versions of Outlook," he said.

The vulnerability is the second major flaw announced by Microsoft this week. On Monday, the software giant warned that a previously unknown vulnerability in a component of its Internet Information Services (IIS) Server 5.0 had allowed hackers to compromise at least one customer's computer system. A representative of the US Army acknowledged on Tuesday that a military server -- but not an Army server -- had been the compromised computer.

The Windows flaw occurs in the way that the operating system handles JScript, its version of JavaScript language -- which itself is known more formally as ECMAScript Edition 3.

An attacker can exploit the vulnerability by either sending a specially crafted script to the potential victim in an email, or by including such a script on a Web site and somehow convincing the user to load the Web page into Internet Explorer.

Email clients and Internet browsers that don't allow scripts to be run will block the attack, Mulholland said. In addition, Outlook Express 6.0 and Outlook 2002 would not be vulnerable to an attack launched through HTML email, if the clients are run in their default configurations. Previous versions of Outlook would also not be vulnerable if the Outlook Email Security Update has been applied.

Patches for the various operating systems can be found on Microsoft's Web site and are available through Windows Update.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
69 out of 161 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Middleware engineer top tier investment bank 6 month contract

Shell scripting on UNIX based systems. SWIFT message formats Middleware Engineer: my client is a tier 1 investment bank who are in urgent need of a ...

Application Support - Fixed Income Derivatives - SQL UNIX PERL SHELL

What is essential is a very strong background in scripting Shell, Perl, Ksh. Please send me a Word CV or pass this message on to anyone you know who ...

Web Applications Developer

NET (VB Script/ C#), JavaScript, XHTML, CSS, XML etc) are required as well as proficiency in the Adobe Studio CS3 Suite, Visual Studio and MS Office. ...

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal