Security

New Internet Explorer Vulnerability

March 18, 2006

If your Internet Browser of choice is Internet Explorer, make sure and read this:

Microsoft’s Internet Explorer browser crashes when attacked through a new unpatched vulnerability, security companies warned Friday.

The zero-day bug occurs within the “mshtml” library when a malformed HTML tag with an abnormally large number of script handlers is fed to the browser. According to the researcher who posted the initial description to the Bugtraq security mailing list, attackers can easily crash IE by flooding its buffer.

The researcher, Michal Zalewski, also released proof-of-concept code that crashes the latest IE release on a fully-patched edition of Windows XP SP2.

Symantec noted in an alert to customers of its DeepSight system that its staff had confirmed the proof-of-concept code crashed IE in some, but not all, situations. Also on Friday, rival McAfee released a new signature to anti-virus customers that detects the proof-of-concept exploit.

Because the vulnerability can be exploited by a single malicious HTML tag, IE could be brought to its knees if its… user simply surfed to a nasty Web site. Symantec, however, warned that the bug may be even more serious. “Further investigation in the details of exploiting the vulnerability to determine the possibility of code execution are currently under way,” the company’s advisory read.

If that’s the case, IE users may face a new major hijack risk.

Pay close attention to this next part:

There are no known work-arounds, and Microsoft did not immediately respond to questions about its plans for the vulnerability.

“Until more information is available it is advised that all users take extra caution in their browsing activities, and limit web access to trusted web sources only,” Symantec recommended.

Zalewski, however, noted that other browsers, such as Firefox and Opera, were not susceptible to the attack, implicitly advising users to consider an alternate browser.

Finally, he pre-empted Microsoft, which always criticizes researchers who disclose bugs before the Redmond, Wash.-based developer can create a fix, with a blast of his own.

“I eagerly await due reprimend [sic] from Microsoft for not disclosing this vulnerability in a manner that benefits them most,” Zalewski said in his Bugtraq posting.

Back to CCT Blog Home Page

Did you find this information beneficial? Do you have other tips or questions? Use this handy form below and let us know:

LINK

designer

CCT

Are You Ready?

When you are ready to get more specific information about your project, click here and fill out our handy online form for a free web design quote.

Get My Free Quote

you need a website?
we can help

    order a project

    arrow

    Recent Posts

    In Web Design

    Domain Name Services fake letter.

    Security

    Domain Name Services Scam - Kind of

    Mar 18, 2006

    If your Internet Browser of choice is Internet Explorer, make sure and read this: Microsoft’s Internet Explorer browser crashes when attacked th...

    Captivating Website Design - Morehead City NC

    Security

    Web Design Basics

    Mar 18, 2006

    If your Internet Browser of choice is Internet Explorer, make sure and read this: Microsoft’s Internet Explorer browser crashes when attacked th...

    Dynamic Web Design in Morehead City NC

    Security

    Three Common Web Design Mistakes

    Mar 18, 2006

    If your Internet Browser of choice is Internet Explorer, make sure and read this: Microsoft’s Internet Explorer browser crashes when attacked th...

    arrow

    Go to our blog