Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Latest IE6 vulnerability explored

Joris Evers CNET News.com

Published: 30 Aug 2005 16:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new, unpatched flaw in Internet Explorer could let miscreants surreptitiously run malicious code on Windows PCs, according to the discoverer of the bug.

The problem affects Internet Explorer 6 (IE6) — the latest version of Microsoft's Web browser — on computers running Windows XP with Service Pack 2 and all security patches installed, Tom Ferris, an independent security researcher in Mission Viejo, California, said in an interview on Monday. Other versions of Windows and IE may also be vulnerable, he said.

The security hole allows for "full-blown remote code execution", Ferris said. "If a user browses to a bad Web site, malicious software can be installed on their PC without their knowledge."

Ferris claims credit for discovering the problem and said he informed Microsoft of the flaw on 14 August. He reported some basics of the bug on his Security Protocols Web site on Saturday, but he is not sharing more details to prevent information from getting into the wrong hands.

A Microsoft representative late on Monday confirmed the company received Ferris' report. The software firm can't confirm whether the flaw exists, but it is investigating the report, the representative said. "At this time, there are not any attacks, and there are not any risks" to users, she said.

Ferris said he provided Microsoft with details on the bug, including computer code to prove the existence of the problem. On his Web site, Ferris shows a screenshot of a crashing IE 6 Web browser, which he said was caused by the same bug.

Upon completion of the investigation, Microsoft will take the appropriate action to protect users, the representative said. This may include providing a security update through its monthly patch release or providing an out-of-cycle security update, she said.

There are several unpatched vulnerabilities in IE 6, according to Secunia. The security monitoring company has issued 69 alerts on the Web browser since 2003; almost one-third of those security bugs remain unpatched, according to Secunia's Web site. Secunia has yet to put out an advisory on this latest IE security issue.

Ferris has found bugs in Microsoft software before. Earlier this month, Microsoft credited him with reporting a bug in a Windows feature called the Remote Desktop Protocol that could allow an attacker to remotely restart Windows systems.

Ferris recommends people pick a different Web browser or use caution when surfing the Web to protect against any exploitation of the latest IE flaw and other browser bugs. Microsoft, as always, urges users to apply all available software patches and run updated security software.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
70 out of 160 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters