November 26, 2003

New critical vulnerabilities discovered in IE

Five holes are in IE 6.0, other versions may also be impacted

A set of new security vulnerabilities have been discovered in Microsoft Corp.'s Internet Explorer (IE) Web browser which used together could allow hackers to compromise user PCs, researchers warned Tuesday.

The five vulnerabilities have been reported in IE 6.0, although other versions may have been affected, according to a bulletin released by security company Secunia Ltd.

The scripting flaws could allow hackers to bypass security and compromise systems, giving them access to sensitive information and cross-site scripting, according to Secunia.

The Copenhagen, Denmark, company has classified the vulnerabilities as "extremely critical" and is advising all IE users to disable Active Scripting or "use another product."

"If they care about Internet security, users should make sure to disable active scripting," Secunia Chief Technology Officer (CTO) Thomas Kristensen said Wednesday.

Microsoft is currently investigating the new vulnerability reports but is not aware of any active exploits or customer impact at this time, according to a representative for Microsoft in the U.K.

Upon completion of its investigation, Microsoft may release a fix in its next monthly security update or an out-of-cycle fix if needed, the representative said.

However, Kristensen said he doubts that the software giant will break its monthly patch release cycle to address the issues.

"I would be happy to see them break their cycle because it affects customers, but I doubt it," he said.

The security flaws were originally discovered by Chinese security researcher Liu Die Yu, who published the vulnerabilities and proof of concept evidence Tuesday.

The Microsoft representative said that the company is "concerned that the new reports of vulnerabilities in IE were not disclosed responsibly, potentially putting computer users at risk."

The company advised users to download its latest IE cumulative patch, released Nov. 11, while it looks into the new vulnerabilities.

Close

On Twitter now

Application development

Powered by Twitter

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive InfoWorld Resource Alerts

Subscribe to the Developer World Newsletter

Receive a weekly roundup about the art and science of software development.

©1994-2009 Infoworld, Inc.