Feeds

'Critical' IE bug threatens PC users

Oh dear, it's been a bad week

Internet Security Threat Report 2014

A dangerous new exploit in Internet Explorer could put PCs and data at risk, Microsoft has admitted.

The flaw, for which code has already been published on the internet, could be exploited to set an email-borne virus free on the unsuspecting public.

Potential viruses could come as an attachment that conceals the code, or could possibly redirect users to a site that will unleash the code on the user's machine, leaving the computer open to remote attack. Once the PC is being controlled by a malicious user, it can then be used to launch attacks on other PCs.

Even supposedly fully patched versions of Internet Explorer 6 are vulnerable to the flaw, it seems, as are users with XP Service Pack 2.

However, Microsoft has no plans to patch it until its next security update is released. This is despite some security companies rating it as a high level threat.

In a security advisory on its website, Microsoft outlined the threat: "We have seen examples of proof of concept code but we are not aware of attacks that try to use the reported vulnerabilities or of customer impact at this time.

"Microsoft has determined that an attacker who exploits this vulnerability would have no way to force users to visit a malicious website."

Instead, it has warned users of its browser products to be careful when opening email attachments and to avoid untrusted websites. It has also recommended that users disable Active Scripting in their browser in an attempt to reduce their exposure to attack.

The other option is to choose an alternative browser, such as Firefox or Opera. However, even these browsers are not as safe from attack as they were once considered.

Firefox has been subject to a number of flaws over the past year, including one that could leave its users more vulnerable to phishing scams. Meanwhile, a report published in September by Symantec rated Internet Explorer as safer than Firefox. The report found some 25 flaws in Mozilla's Firefox internet browser, almost double the number it discovered in IE.

However, it has been a tough week for Microsoft - this is the third security flaw it has had to investigate in the past seven days. On Tuesday, it admitted it was looking into a security flaw that could leave Windows PCs open to remote control, while earlier in the week it also alerted users to a vulnerability that could cause the Internet Explorer browser to crash.

Copyright © 2006, ENN

Remote control for virtualized desktops

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Seattle children’s accelerates Citrix login times by 500% with cross-tier insight
Seattle Children’s is a leading research hospital with a large and growing Citrix XenDesktop deployment. See how they used ExtraHop to accelerate launch times.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?