| | | RssFeeds
 
Get Free Newsletter Search   Search Search
         

Follow Us:

 
 
NC Print 
January 2010
Editorial
HP Targets Premium Workstation Market with New Features
By Invitation

»The Analyst Angle

»ProductivIT

»Technology & Risks

Microsoft Dangles ROI Bait to Push Exchange 2010 Adoption
Business Intelligence Tracks Flu Cases in Upstate New York
Next-Gen BI Is Here

» Open Source BI Makes a Beginning

» BI: New Models Emerge

» Better Transparency Through BI

» Marrying Strategic Intelligence with Operational Intelligence

» Small and Medium Business(es) Intelligence

» Column-oriented Technology Conditions RDBMS for OLAP

Tulip Telecom Hopes to Ride High on New Wings of Fiber
Muralikrishna K
On the Record

»Tony Tsao

»Pascal Laik

»Tom Gillis

»Richard Clifton

»Justin Rattner

No, the Cloud Won’t Evaporate
Case Study

»The Power of a Simple SMS

»Web 2.0 Leads Collaboration Revolution at Mahindra Group

What CEOs Want From CIOs
Coke's RFID-Based Dispensers Redefine Business Intelligence
7 Cloud Computing Myths Busted
How Indian CIOs Stack Up
Is ‘free’ actually free?
In the News
 EDGE 2009

Read More About the Best IT Implementations in the Country

 
       Read more >> 

Archive
 

Microsoft Warns Of Zero-Day Flaw in Older Versions of IE


Pointer reference flaw could enable attackers to run their own code on IE machines, software giant says

 By Tim Wilson, DarkReading, November 30, 2009, 1200 hrs

Microsoft says it is investigating public reports of a vulnerability in older versions of Internet Explorer that could enable attackers to inject their own code onto Windows PCs.


 

In a security advisory, Microsoft says the vulnerability primarily affects Internet Explorer 6 and 7, as well as related service packs. The older IE 5.01 Service Pack 4 and the newer IE 8 are not affected.

 

"The vulnerability exists as an invalid pointer reference of Internet Explorer," Microsoft says. "It is possible under certain conditions for a CSS/Style object to be accessed after the object is deleted. In a specially-crafted attack, Internet Explorer attempting to access a freed object can lead to running attacker-supplied code."

 

Although the vulnerability is public and no patch is yet available, Microsoft says it does not know of any active exploits yet. Once it finishes its investigation, Microsoft says it will respond, possibly through an out-of-cycle update or a scheduled Patch Tuesday release.

 

Microsoft also says it is working with partners to "monitor the threat landscape and take action against malicious sites that attempt to exploit this vulnerability."

 

As a workaround, Microsoft says users of the affected versions of IE could run their browsers in restricted mode (Enhanced Security Configuration). Microsoft also says systems configured with fewer user rights may be less likely to be affected.

Print this Page   E-mail this Page
RATE THIS ARTICLE
 Worse   Better 
Comment:*
First Name:*
Last Name:*
Company:
City:*
E-mail:*
Verification Code:*

Type the characters you see in the picture above.
 
  Reset

Comments >>

1
No Comments to display

Disclaimer >>

 

 

 Global CIO

Global CIO: The Top 10 CIO Issues For 2010

For CIOs, 2010 will require new emphases on customers, revenue, external information, and a passion for rapid change           
           Read More >> 

 

 Editor's Blog

IT Can Accelerate Inclusion

        

Read more >>  

 

 CIO Profile

Satish Pendse Muralikrishna K

VP and Head, Computers & Communication Division, Infosys Technologies

 Read more >>  

 

 International News

Facebook Hit By Clickjacking Attack

Social network targeted by emerging brand of attack that's hard to kill

 Read more >>

 

        

 Work Smart

Archive your mail      


Read more >>  

 

ADVERTISEMENTS >>

 
Powered By: ssCMS 2.2.0.0