ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

IE security hole launches e-mail attachments

Erich Luening, CNet News CNet

Published: 02 Apr 2001 08:06 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security hole in Microsoft's Internet Explorer Web browser can cause the browser to automatically open e-mail attachments that could be used by an attacker to execute malicious code, the company has warned.

The flaw exists in versions 5.01 and 5.5 of the browser, and affects how Internet Explorer processes attachments to HTML e-mail encoded with the Multipurpose Internet Mail Extensions (MIME) standard, Microsoft said in a security bulletin posted to its Web site.

MIME is a widely used Internet standard for encoding binary files as e-mail attachments.

The flaw could result in IE launching an e-mail attachment automatically, which could leave computers vulnerable to malicious attack, Microsoft warned in the bulletin.

Microsoft has developed a patch that can be downloaded from its Web site. The company said Internet Explorer users should download and install the patch immediately. A fix for the MIME problem is also included in IE 5.0 Service Pack 2, so users who have already downloaded the service pack do not have to download a new patch, according to the company.

Microsoft said the problem can also be avoided if file downloads have been disabled in the corresponding "Security Zone" in Internet Explorer. That setting is not a default in Internet Explorer and would have to be selected by the user, Microsoft warned.

The company said the hole could enable attackers to run a program of their choice on the machine of an unsuspecting user.

Such a program would be capable of taking any action on the affected machine, including adding data, changing or deleting it, communicating with Web sites or reformatting a hard drive.

"In order for the attacker to successfully attack the user via this vulnerability, she would need to be able to persuade the user to either browse to a Web site she controlled or open an HTML e-mail that she had sent," Microsoft stated in the bulletin.

The security bulletin comes just one day after bug hunter Georgi Guninski said he had discovered a bug in Internet Explorer that could let malicious hackers read the e-mail and computer files of some unsuspecting people.

A software developer, Juan Carlos Cuartango, reported the latest issue to Microsoft and helped prepare a patch for the security hole, according to the company.

Microsoft has been increasingly criticized in recent years for allegedly valuing interoperability between its products over security. In an effort to provide various pieces of software that interact with each other, some security experts say the company has failed in addressing possible holes that could allow malicious hacker exploits.

Security "is an ongoing issue with Internet Explorer because it is such a complicated software that interoperates with many other applications that it is too difficult to figure out all of these vulnerabilities," said Richard Smith, chief privacy officer at the Denver-based nonprofit group The Privacy Foundation.

For instance, Microsoft's Outlook messaging software, which is used by millions of people, played a key role in the rapid spread of viruses including I Love You and Melissa.

Take me to Hackers

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
33 out of 81 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

JavaScript / AJAX / Web 2.0 development role

I have a brand new, exciting opening in Edinburgh for a rapidly expanding software house poised to further attack the market on the back of recent ...

C# ASP.Net Developer - Retail - Hertfordshire - 45K - Permanent

.Net .Net .Net .Net We require a C# ASP.Net Developer is required to join an exciting team working on development of a successful e-commerce web site ...

C# ASP.NET Developer Required URGENTLY!!!!!!

Are you an experienced developer using C# ASP.NET? Have you completed numerous contracts in web site development using these technologies? If so, ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment