Feeds

Security glitch bites IE7 beta

Crash test dummy

Secure remote control for conventional and virtual desktops

Researchers have discovered a security vulnerability in a preview version of Microsoft's Internet Explorer 7 (IE7) browser just days after its release. A denial of service bug in IE 7 beta 2 creates a means for a hacker to crash the software and potentially execute arbitrary malware on PCs running the code, according to security researcher Tom Ferris. Ferris has produced a proof of concept demo to illustrate his concern that IE 7 beta 2 builds are exposed to the "medium risk" flaw.

Microsoft has responded in a posting on its official IE development blog to confirm the the bug identified by Ferris does crash IE 7. "However, we did not find that the bug was exploitable by default to elevate privilege and run arbitrary code," it said. Microsoft said it identified the bug itself during a code review and that a fix was already in development. Redmond adds that the bug is difficult to exploit and isn't the subject of current hacker attacks.

Other issues with the latest build of the browser have been unearthed during early testing. Compatibility problems with McAfee security software and glitches that cause the browser to crash when visiting certain websites have emerged. Since IE 7 is undergoing beta testing, these kind of bugs are to be expected. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?