main
Report a problem

Scripting flaws pose severe risk for IE users

Daniel Fleshbourne   on 26 November 2003 - 08:39 · 3 comments & 453 views

Advertisement (Why?)
A set of five unpatched scripting vulnerabilities in Internet Explorer creates a mechanism for hackers to compromise targeted PCs. The vulnerabilities, unearthed by Chinese security researcher Liu Die Yu, enable malicious Web sites and viruses to bypass the security zone settings in IE6. Used in combination, the flaws might be exploited to seize control of vulnerable PCs.

Proof of Concept exploits have been released by Liu Die Yu to validate his warnings. Microsoft has yet to patch the flaws. But users can protect themselves against the flaws by disabling active scripting or by using an alternative browser. Thomas Kristensen, CTO of security Web site Secunia, told The Register that the five distinct vulns could used in combination to install executables (viruses, Trojans and porn diallers). Secunia describes the vulnerabilities as "extremely critical".

Despite this, Kristensen warns that Microsoft is unlikely to break its newly instituted monthly release cycle to release a stand-alone IE patch unless a vulnerability was widely exploited. Pending the availability of a patch, Secunia advises all IE users to disable active scripting.

View: The full story
News source: The Reg

Post a comment · Send to friend Comments · There are 3 additional comments

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)