Detailed information on a brace of unpatched vulnerabilities in Internet Explorer has been posted onto a dull disclosure mailing list. The flaws involve a cross-zone scripting vuln and a bug in IE"s Local Resource Access and pose an "extremely critical" risk to Windows users, according to security firm Secunia. The vulnerabilities affect both Internet Explorer 6 and Outlook. Secunia has confirmed the vulnerabilities in a fully patched system with Internet Explorer 6.0. Improved security features in the XP SP2 reportedly block exploitation but users would be ill advised to rely on beta code for protection. SP2 doesn"t help users of earlier versions of Windows who are also at risk.
The vulnerabilities are actively being exploited in the wild to install adware on users" systems, security researchers warn. Other exploits - include computer viruses - based on the same techniques of tricking users into visiting a maliciously constructed website housing malign script could follow.