You are here: silicon.com > Software > Applications

Applications

IE flaw - Microsoft releases patch

Protect your 'zones'

By Robert Lemos

Published: 6 February 2003 11:23 GMT

Microsoft on Wednesday advised Internet Explorer users to apply a patch for a vulnerability that could allow a website administrator to steal data or take control of a person's PC.

The flaw occurs in Internet Explorer's domain security, the technology that keeps applications running in the internet domain from accessing data on the PC or local domain, for example.

"In the worst case, this vulnerability could allow an attacker to load a malicious executable onto the system and execute it," the advisory said. The update is available from Microsoft's website.

Internet Explorer uses security domains, or 'zones', to limit what certain websites and HTML (Hypertext Markup Language) pages can do to a person's PC. From the most restricted to the least restricted, the zones are categorised as Restricted, Internet, Trusted and Local. By taking advantage of this flaw, a web page could bypass the protections and use the local, or least restricted, zone.

The patch came two days after the software giant pulled a patch for its Windows NT 4.0 systems, MS02-071, released in December.

"We started getting back reports that some configurations were having problems," said Iain Mullholland, security programme manager with Microsoft security response. "We don't take pulling a patch lightly. We are working on it as hard as we can."

While the occurrence doesn't happen often, Microsoft pulled a patch for Exchange in June 2001, after customers complained the fix had broken their software.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
RF PA Systems Technical Lead, Cambridge

Good understanding of signal distortion mechanisms in both analogue and digital domains. Load pull” techniques. RF PA simulation using ...

Internal Sales Executive - Domain Management Sales Executive

Internal Sales Executive - Domain Management London 25k Base, 45k OTE + Excellent Benefits Our client is an integral part of leading group of ...

Senior Server Specialist

Several years experience with Windows Client & Server platforms, including Windows NT 4.0, Windows 2000, Windows 2003 & XP. Detailed knowledge of ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: