ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Dangerous exploit released for old IE hole

Dawn Kawamoto CNET News.com

Published: 22 Nov 2005 09:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Exploit code for a new flaw in Internet Explorer could put systems at risk of remote attack, security experts warned on Monday.

The exploit code aims to take advantage of the "extremely critical" vulnerabilities in IE 5.5 and IE 6 running on XP Service Pack 2 (SP2), and IE 6 running on Windows 2000 SP4, security company Secunia said in advisory.

Once a PC user is tricked into visiting a malicious Web site, the exploit can be triggered automatically, without the user doing anything.

"An attacker could use the exploit to run any code they want to on a person's system," said Thomas Kristensen, Secunia's chief technology officer. "It could be they want to launch some really nasty code on a user's system."

The flaw lies in a Javascript component of IE, according to an advisory from SANS Internet Storm Centre.

Microsoft has not released a patch for the hole exploited by the code. People can attempt to work around the problem by either shutting off JavaScript or using another type of browser, security companies advised.

Security researchers said the IE vulnerability has been known for the past six months, but had previously been seen as a conduit for denial-of-service DoS attacks rather than the remote execution of code. DoS attacks, which attempt to crash a system by flooding it with data, are typically considered less-severe security risks.

"The vulnerability itself has been known about for a while, but it was only a problem for a denial-of-service attack that would sometimes cause IE to crash," said Johannes Ullrich, chief research officer for the SANS Institute. "Up until now, no one knew how to mark the code and find it in memory to execute a remote code attack."

The exploit code was published by an organisation called Computer Terrorism.

Because the flaw was initially believed to involve only a potential DoS attack, Microsoft never issued a patch for the problem, Ullrich said. He added it is not yet known whether Microsoft will spin out a patch for the flaw immediately or wait for its monthly patch cycle.

A Microsoft representative was not able to comment early Monday on the flaw or the exploit, but did say that the company is investigating reports of the possible vulnerability for customers using Internet Explorer while running Windows 2000 SP4 and Windows XP SP2.

"We have also been made aware of proof-of-concept code that could seek to exploit the reported vulnerability but are not aware of any customer impact at this time," the representative said.

Microsoft, upon completion of its investigation, will take appropriate action to protect its customers by providing a patch as part of its monthly security bulletin program or in a separate security advisory, the representative added.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
67 out of 125 people found this useful


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Front End Developer XHTML, CSS, Javascript, W3C

Front End Developer XHTML, CSS, Javascript, W3C Reports to Functional Head of Visual Design and relevant Project Manager Type of position: Perm ...

Web Developer, HTML, CSS, JavaScript - 28K, Bangor - North Wales

Huxley Associates in Manchester are once again working for one of their key clients based Chester to help them look for a Web Developer (HTML, CSS, ...

HTML, XHTML, JAVASCRIPT and CSS UI Development Media

HTML, XHTML, JAVASCRIPT and CSS UI Development Media Huxley Associates media client based in the Centre of London are looking to add a UI developer ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments