Be Careful With F1!
By Bryan on March 3, 2010 | Vulnerabilities, Microsoft, Windows 2000, Windows XP, Windows Server 2003, Internet Explorer, VBScript, F1 key
Microsoft announced one more IE vulnerability in its advisory . This unpatched vulnerability can affect users of Windows 2000, Windows XP, and Windows Server 2003 that running Internet Explorer. VBScript flaw can be used to run malicious code. Attacker can create a web page that displays an exact dialog box with a suggestion to press F1 key. This accomplishment can terminate malicious code on a victim computer.
Microsoft claims at its advisory : “Microsoft is concerned that this new report of a vulnerability was not responsibly disclosed, potentially putting computer users at risk. We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests. This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed.”
More Vulnerabilities news
Denial-of-service flaw is fixed by Oracle
Recently, Oracle released a patch which fixed denial-of-service vulnerability in the Oracle WebLogic Server, Application Server and iPlanet Web Server. In a security bulletin Oracle warned that "vulnerability may be remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password." Oracle pointed out that a fix for the same vulnerability in the GlassFish Server was released last month. Read more.- Firefox 9.0 and four critical flaws fixed
- Major flaw of Adobe Reader and Acrobat 9.x is patched
- Adobe Reader targeted again: Acrobat vulnerability
- From „White hat“ Charlie Miller was turned to „Black hat“
- Temporary remedy against Dugu
- Malware distribution tendencies 2011
- Mac OS X Lion flaw gives opportunity attacker changing victim’s password
- Flaws have been detected in Symantec Endpoint Protection Manager
- New IE bug may expose your cookies
- Secret is not revealed but Facebook’s flaw is repaired








