Microsoft Explores Another IE Flaw After the Google Attack
By Gina on February 4, 2010 | Vulnerabilities, Microsoft, flaw, Google attack, vulnerability
Microsoft announces its aspiration to investigate another Internet Explorer flaw. This time the vulnerability is different from the one used to attack Google and the U.S. companies. As a result of this flaw, the IE users may loose their information by a fault of unknown disclosure. This can happen for those who run their browsers on some older operating systems.
For that reason Microsoft software specialist said in an advisory, that the vulnerability exists, but there were no attacks grounded of this hole in IE. The flaw is not connected to the Google attack which was announced earlier. This time the vulnerability could be exposed by malicious websites designed to take advantage of the Internet Explorer defect or to perform a web-based attack by compromising a website via malicious advertisement or the user-generated content. This may lead the user into constantly visiting the disreputable website.
Microsoft's announced concern about the new flaw in the Internet Explorer could affect those running Windows XP and IE on Windows XP. The software specialists notice, that those who run their browsers on Windows Vista and Windows 7 aren't vulnerable, because they run on a “protected mode” by default.
Nevertheless, McAfee spokesman Joris Evers also said, the latest issue doesn't allow the attacker to achieve full control of the operating system. However, this vulnerability can't be missed, because it can be crucial for the user's personal information or system information, which can be used in a follow up attack.
Microsoft also said it may take some time to investigate and release an update for this flaw as it was done during the latest Google attack. The software maker suggested an automated “Fix it” that can turn on the protected mode for those running IE 6.
More Vulnerabilities news
Adobe Reader PDF patches the flaw disclosed at Black Hat
As the hole in an Adobe’s Reader was disclosed at the conference of Black Hat security conference, Adobe patched the flaw at last. Today Adobe released security update to patch the hole. At July's Black Hat event in Las Vegas, Charlie Miller found out about the vulnerability where he told about how the open-source BitBlaze toolkit could boost bug-hunting productivity. He also added that the bug was in Reader's and Acrobat's font parsing. Read more.- iPhone OS is not bulletproof
- All your base are belong to us: how to protect your router from DNS rebinding
- Same Skype Vulnerability is Used Again
- Competition Among Browsers: Keep the System Secure
- Apple Released Safari Update
- A Bug Found in OpenSSL
- Google Engineer Disclosed Window's DEP Flaw
- Be Careful With F1!
- Top 10 TLDs Used by Botnets For CnC
- Mistakes to Avoid on Social Networks








