Exploit code attacks unpatched IE bug
Help! SP2 security breached
Posted in Enterprise Security, 10th January 2005 12:08 GMT
Free whitepaper – Vulnerability management buyer's checklist
Code which exploits a vulnerability in the HTML Help control of Internet Explorer has been released onto the net. Secunia has upgraded the vulnerability, uncovered in October 2004, to "extremely critical". Even users who have upgraded to Windows XP SP2 with all available patches are affected, the security reporting firm warns.
"The vulnerability can be exploited by malicious people to place and execute arbitrary programs on a client system if a user visits a malicious website. It doesn't require user interaction," Thomas Kristensen, CTO, told El Reg.
"The vulnerability was originally discussed as the Drag'n'Drop vulnerability back in October 2004. The new development only utilises flaws in the HTML Help control. Users can only protect themselves by disabling ActiveX support or using another product."
Secunia has published an online test for the vulnerability here. ®
Related stories
Mozilla and Firefox flaws exposed
MS quashes infamous Bofra bug
IE exploits top web security threat list
Security holes that run deep


Airport insecurity: the case of lost laptops
Reducing messaging and web security costs with managed services
Avoiding 7 common mistakes of IT security compliance
Extended Validation SSL Certificates
Feds: Hospital hacker's 'massive' DDoS averted
Microsoft knew of nasty IE bug a year before attacks
BlockMaster SafeStick hardware-encrypted USB drive