You are here: silicon.com > Software > Security Strategy

Security Strategy

'Critical' IE flaw breaks monthly Microsoft security update

Take that, phishers…

Tags: internet explorer

By Robert Lemos

Published: 3 February 2004 08:45 GMT

Microsoft broke its once-a-month schedule on Monday to fix a critical flaw in Internet Explorer that could allow malicious coders to take control of an unwary user's PC.

The most serious problem, known as a cross-domain security vulnerability, affects all versions of Internet Explorer running on Windows NT, 2000 and XP. A person with a vulnerable system who clicks on a link in an HTML email or goes to a hostile website could allow an attacker to run code on their computer, Microsoft said in its advisory.

The seriousness of the issue forced the company to release the latest fixes before its normally scheduled date, the second Tuesday of the month.

"We evaluated the public nature of the vulnerabilities and heard from customers that this was impacting them, and we made the decision to publish," said Stephen Toulouse, security program manager with Microsoft's Security Response Center.

The update also fixes two other security flaws, including one that gained a lot of attention for its ability to make fake websites look real. Known as the phishing flaw, the problem allows scam artists to forge the address in the Internet Explorer browser's address bar to display an address different from the actual site to which the user was being sent.

Scammers typically use the flaw to build a site that looks like an official website and then send bulk email messages that draw unsuspecting victims to the site. In January, the scam directed users to a site that looked like the official Federal Deposit Insurance Corp. website, asking for personal information to verify their identity. Instead, the fake website, based in Pakistan, collected the information in an attempt to steal from victims.

A third flaw allows a malicious website or HTML email to download a file to a user's computer, without asking permission, when the user clicks on a specially crafted link.

Microsoft advised Windows users to update their software quickly.

Breaking from Microsoft's monthly patch schedule will not happen often, said Toulouse.

"We do believe very much in sticking to the once-a-month thing - our customers like the predictability," he said. "But we have always said that if we have to go out of the cycle to protect our customers we would do that."

Robert Lemos writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
JAVA DEVELOPER

Our client is seeking to recruit a Java Developer.Business Function: Application DevelopmentLine Manager Job Title: Software Development ...

QA Specialist/Web Tester, HTML, CSS, XML

Required Skills: - 2 years+ QA/Testing experience - New Media Agency experience or similar - Cross Browser Testing, Usability and Accessibility ...

Quality Assurance Specialist- Digital Agency

Skills needed- Knowledge of HTML, CSS, and XML, to help diagnose errors and suggest fixes Cross-browser expertise, in testing and identifying fixes ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: