ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Critical Internet Explorer patch 'does not work'

Patrick Gray ZDNet Australia

Published: 08 Sep 2003 09:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A patch released by Microsoft to fix a critical security vulnerability in Internet Explorer does not work, according to security experts.

The "object type" vulnerability was discovered by eEye Digital Security around four months ago. A patch was released on 20 August -- and then re-released on 28 August, because under some circumstances it caused problems for some non-default operating system installations -- and looks due for yet another re-release because it simply doesn't fix the vulnerability it is supposed to, eEye said.

The vulnerability can be exploited by crafting a malicious HTML file that, when viewed by an Internet Explorer browser, extracts and executes malicious code.

Speaking to ZDNet Australia by phone from the US, Marc Maiffret, eEye's chief hacking officer, said the vulnerability is particularly critical because it doesn't take a lot of effort to take advantage of. "It's pretty serious just because it's so easy to exploit... it doesn't require someone to know how to write buffer overflow exploits or anything like that."

Maiffret says Microsoft should have done a better job to begin with. "How do you take four months to fix something this simple and then not fix it correctly?" he asked. "It seems like they are taking security seriously... [but] at the same time I don't think they're really investing."

The lack of suitably skilled security engineers within the company is one reason Maiffret says this incident -- described by the researcher who discovered the flaw in the patch as a "pathetic oversight" -- has occurred. "A lot of it comes from having the right people in-house," Maiffret said. "They have some very smart guys in there, but they definitely don't have enough."

The problem with the security fix was first made public by malware.com and Maiffret sincerely doubts that Microsoft were informed prior to the disclosure. "They discovered it and they're getting the information out there... I'm not sure if they gave Microsoft the information, which is usually the best way," he said.

Prior to the release of the patch, Maiffret's team looked over the patch and didn't see any problems, but he says it was a quick "once over" -- not a detailed audit. "[Our] researchers were just helping out, it's not like MS were paying us for this," he said. Microsoft use external security code auditors, which in this case were not doing enough, Maiffret says.

Concerned users can disable active scripting on their browsers to mitigate the vulnerability until Microsoft makes a patch available.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
54 out of 117 people found this useful


Full Talkback thread

1 comment

  1. This apparrently relates to the Trojan horse Back... Morten Lange

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Fix Protocol Analyst - Contract - London City / NY

Fix Protocol Analyst - Contract - London City / NY My client is seeking an experienced FIX protocol analyst to join their team on a contractual ...

FIX Analyst / Support - Contract - Inv Banking - London

FIX Analyst / Support - Contract - Inv Banking - London This role is for an experienced FIX Protocol analyst. You will have a strong background and ...

Java Connectivity Developer Equities Trading - Java, FIX

From a technical perspective good Java experience is required, knowledge of UNIX and FIX is strongly preferred. Java/UNIX/FIX/ SYBASE. A Junior level ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation