Skip to content

Biting the hand that feeds IT

The Register ®

Security:


Related Whitepapers

[Print][Mobile][Alerts]

Exploit code unpicks IE flaw

SP2 no defence

Published Tuesday 22nd November 2005 11:24 GMT

Hackers have created a potent exploit for a six-month old vulnerability in Internet Explorer which was previously believed to be only a Denial of Service risk. A fresh exploit posted on computerterrorism.com proves that the security bug can be exploited to gain system access, even on systems running Windows XP with Service Pack 2. The flaw stems from a failure by IE to properly handle requests to the window() object.

Successful exploitation involves tricking a Windows user running IE into visiting a maliciously constructed website contain hostile JavaScript code. Users of both IE 5.5 and 6.x are potentially at risk. "Currently, the only way to protect against exploitation of this vulnerability is by disabling active scripting or by using another browser," said Thomas Kristensen, CTO of security notification firm Secunia.

Microsoft's holding statement on the issue can be found here. ®

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
whitepaper title

The Perfect (Virtual) Marriage

Get consistent virtual machine storage savings of 50% (often as high as 90%) with virtually no performance impact with NetApp deduplication..
whitepaper title

Gartner Paper: US Data Centers

U.S. enterprise data centers face considerable space and energy constraints over the next few years. Download this free independent report to read more..
Whitepapers

Top 20 storiesAll The Week’s HeadlinesArchiveSearch