main
Report a problem

Microsoft: IE security hole worse than reported

Keldyn   on 08 December 2002 - 07:07 · 52 comments & 2297 views

Advertisement (Why?)
Microsoft on Friday raised its threat rating for a security flaw in its Internet Explorer browser to "critical," in response to criticism of its initial assessment of the hole's danger.

A representative of Microsoft, which has come under fire for its security policies, said the company had changed its original rating of a flaw in IE versions 5.5 and 6 as a result of comments posted to the Bugtraq online bulletin board by a security consultant.

"Microsoft has given this vulnerability a maximum severity rating of moderate," Larholm wrote. "Great, so arbitrary command execution, local file reading and complete system compromise is now only moderately severe, according to Microsoft."

Larholm characterized the initial rating as an attempt to downplay the second major Internet security bug found in a Microsoft product in about two weeks. The first security hole exposed millions of Web servers and PCs to potential hacking. That flaw likely affected the more than 4 million Web sites using Microsoft's Internet Information Server software.

"It seems like Microsoft is deliberately downplaying the severity of the vulnerabilities in an attempt to gain less bad press. It sure would look bad to release two critical cumulative updates in just two weeks, but that is exactly what has been done," Larholm wrote.

But Microsoft said Friday that it had simply missed an important detail when making its initial assessment of the flaw. By causing the company to do additional testing, Larholm's postings alerted Microsoft to the error.

View: Full Story
News source: C|Net

Post a comment · Send to friend Comments · There are 52 additional comments
(1 reply) #1 on 01 Jan 1970 - 00:00
#1.1 Neobond on 08 Dec 2002 - 19:46
What ever happened to K-Melon? That seemed very promising
(1 reply) #2 on 01 Jan 1970 - 00:00
#2.1 Neobond on 09 Dec 2002 - 11:23
[neoquote=#14.1 by warr]lol. m$ users claim themselves to be more intelligent than others. [/neoquote] That post alone makes me want to question your intelligence and is typical of the fanboy posts we hate so much here.
#3 Neobond on 09 Dec 2002 - 11:32
Lets not forget people, this post came from a site who thinks Apple OSX (10.0) is better than Windows XP (not SP1) and Netscape 6.0 was supposed to be better than IE 6.0 (which they then corrected later) C|Net has always been biased towards Microsoft I don't see this changing anytime soon. When I see posts like these I feel grateful that these critical holes are patched with Windows Update and wide scale press. Maybe Microsoft suck at making a secure browser but they are market leaders in patching their own software with Auto-update or regular Windows Update visits. All software is flawed, all I worry about is [b]how[/b] microsoft can implement fixes and they do this fine IMHO.
(1 reply) #4 on 01 Jan 1970 - 00:00
#4.1 Neobond on 09 Dec 2002 - 16:18
[neoquote=#2.6 by antareus]What is this, an informed opinion on neowin? What are you doing here Dess? [/neoquote] another troll? who rattled your cage

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)