IE bugs open up even XP SP2 to attack

Oct 21, 2004 12:00 AM
Filed under Security

Two new vulnerabilities in Internet Explorer 6.0 were unveiled by a security firm this week that hackers could exploit to bypass security features even in Microsoft's most secure OS, Windows XP SP2.

Two new vulnerabilities in Internet Explorer 6.0 were unveiled by a security firm this week that hackers could exploit to bypass security features even in Microsoft's most secure OS, Windows XP SP2.

According to Danish security company Secunia, the "highly critical" vulnerabilities stem from a flaw in IE's drag-and-drop feature and in the browser's security zone.

Hackers could exploit these bugs by enticing users to malicious websites, where specially crafted files -- including image and help files -- could compromise the PC, leaving it open to attack or hijack.

Both bugs can be exploited to circumvent Windows XP SP2's Local Computer zone lockdown security feature, said Secunia.

"This has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2," wrote Secunia in its online alert.

As is its usual practice when it touts critical problems in IE, Secunia recommended that users either disable Active Scripting in the browser, or switch to an alternate, such as Mozilla's Firefox.

 

 
Follow us on Facebook and Twitter
 
Tags
 
 
 
 
 
Top Stories
Major network outage at Anittel
Business customers disconnected most of yesterday.
 
Huawei knocks local revenue out of the park
Still bathing in poor light security-wise.
 
Sophos focus on channel education
Karen Delaney is the new channel director.
 
Sign up to receive CRN email bulletins
   FOLLOW US...
Latest Comments
Polls
Is your business doing as well now as it was at this time last year?


   |   View results
Yes
  33%
 
No
  52%
 
The same
  15%
TOTAL VOTES: 391

Vote now
CRN Magazine

Issue: 315 | May 2013

CRN Magazine looks in-depth at the emerging issues and developments for the channel, and provides insight, analysis and strategic information to help resellers better run their businesses.