You are here: silicon.com > Software > Security Strategy

Security Strategy

Attack code alert over unpatched IE flaw

Exploit in the wild...

Tags: flaw, exploit

By Joris Evers

Published: 15 September 2006 08:45 GMT

Computer code that could be used to hijack Windows PCs via a yet-to-be-patched Internet Explorer flaw has been posted on the net, experts have warned.

The code was published on public websites, where it is accessible to miscreants who might use it to craft attacks on vulnerable Windows computers. Microsoft is investigating the issue, a company representative said in a statement on Thursday.

The representative said: "Microsoft's initial investigation reveals that this exploit code could allow an attacker to execute memory corruption." As a workaround to protect against potential attacks, Microsoft suggests Windows users disable ActiveX and active scripting controls.

The flaw is due to an error in an ActiveX control related to multimedia features and could be exploited by viewing a rigged web page, Symantec said in an alert sent to users of its DeepSight security intelligence service on Thursday. An attacker could commandeer a Windows PC or cause IE to crash, according to the security company.

IE versions 5.01 and 6 on all current versions of Windows are affected, the French Security Incident Response Team, or FrSirt, a security-monitoring company, said in an alert on Wednesday. FrSirt deems the issue "critical", its most serious rating. Microsoft noted that Windows 2003 running Enhanced Security Configuration is not affected.

Upon completion of its investigation, Microsoft may issue a patch for the flaw as part of its monthly release process, the company said. Microsoft is not aware of any attacks that attempt to exploit the new IE vulnerability at this time, it said.

The warning of the new flaw comes only days after Microsoft released its September patches. On Tuesday it released three updates, two for Windows and one for Office. The software maker also released a third version of an Internet Explorer fix after it botched the first two versions of the patch.

In recent months, word of new attacks has repeatedly followed shortly after 'Patch Tuesday'. Some experts believe the timing of the new attack is no coincidence, suggesting attackers look to take advantage of a full month before Microsoft is scheduled to release its next bunch of fixes.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Team/Store Manager - East Wittering

ll lead your team to beat sales, items and services targets, and and exploit opportunities to grow sales. own your patch? You lead the healthcare ...

Basingstoke/Failure Investigation Engineer/35K-40K

Basingstoke/Failure Investigation Engineer/35K-40K The overall purpose of the job is to; + Undertake and document root cause failure analysis for ...

Failure Investigation Engineer wanted Hampshire- Quality QA Assurance

They are looking for a Failure Investigation Engineer to join their Customer Advocacy team. This multi-national medical devices producer, offering an ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: