ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Exploit code increases threat of IE flaws

Dawn Kawamoto CNET News.com

Published: 10 Jan 2005 08:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Three unpatched flaws in Internet Explorer now pose a higher danger, a security company warned, after code to exploit one of the issues was published to the Internet.

Secunia said on Friday that it had raised its rating of the vulnerabilities in Microsoft's browser to "extremely critical", its highest rating. The flaws, which affect IE 6, could enable attackers to place and execute programs such as spyware and pornography dialelrs on victims' computers without their knowledge, said Thomas Kristensen, Secunia's chief technology officer.

Exploit code for one of the vulnerabilities, a flaw in an HTML Help control, was published on the Internet on 21 December in an advisory by GreyHats Security Group.

"In order for us to rate a vulnerability as extremely critical, there has to be a working exploit out there and one that doesn't require user interaction," Kristensen said. "This is our highest rating and is the last warning for users to fix their systems."

The exploit code can be used to attack computers running Windows XP even if Microsoft's Service Pack 2 patch has been installed, Secunia said. The company is advising people to disable IE's Active X support as a preventative measure, until Microsoft develops a patch for the problem. It also suggests using another browser product.

The Secunia advisory also warns of another HTML Help control vulnerability that, when used in combination with a drag-and-drop flaw, could be used to attack PCs -- though in that case, it would have to be with the interaction of the victim. The company first issued an alert about the three security holes in October.

"Microsoft knew of this back in October," Kristensen said. "In my opinion, it's not fair to have a vulnerability known for two months without having an available patch, especially when every little detail [of the vulnerability] is out there."

"Microsoft is now aware of all three issues, and I'm sure they're giving it an even higher priority," he added.

Microsoft said it was investigating the public reports of the exploit, adding that the delay in fixing the IE patch was related to the extensive work needed to produce an effective patch.

"It's important to note that security response requires a balance between time and testing, and Microsoft will only release an update that is as well engineered and thoroughly tested as possible -- whether that is a day, week, month or longer," a Microsoft representative said. "In security response, an incomplete security update can be worse than no patch at all if it only serves to alert malicious hackers to a new issue."

Microsoft is advising people to check its safe browsing guidelines and to set their Internet security zone settings to "high". It also suggests that people continue installing automatic security updates from Service Pack 2.

This latest discovery marks another setback in Microsoft's efforts to shore up its security. When Microsoft launched SP2 in August, chairman Bill Gates touted it as a significant step in fortifying systems against attacks.

Secunia also offers users the ability to conduct an online test of their systems to see if they are vulnerable.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
60 out of 132 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Websphere IT Specialist / Architect

Trouble shoot and fix technical problems, liaising with product management and technical support to organise a patch if necessary. Websphere IT ...

Web Applications Developer

We expect team members to keep abreast of developments in the field and exploit new technologies as and when required. For an application pack please ...

DESKTOP SPECIALIST- Financial Traders- London City (40-45k)

Additional knowledge of energy trading applications, application packaging and imaging, and security patch management would be useful as well as ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment