internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

Microsoft Admits IE Still Flawed
New IE Flaw Emerges That Could Allow Remote Code Execution
Sean Michael Kerner

IE patches Barely a day after Microsoft updated its Internet Explorer browser to patch no less than four separate vulnerabilities, a new flaw has emerged that could allow remote code execution.

In a public advisory issued late Wednesday, Microsoft confirmed that it is investigating public reports of attacks take advantage of the new IE vulnerability, but added that it's thus far seen only what it called "limited attacks."

It did not elaborate on the attacks or on the exact nature of the vulnerability.

Security research firm eEye, however, identified the new vulnerability as an XML Zero-Day (define) flaw. Likewise, Symantec researcher Elia Florio pinpointed the problem as affecting the XML parsing engine in IE 7.

"The vulnerability depends on how certain elements of HTML pages are terminated and therefore could potentially affect not only XML, but also other objects handled by the browser," Floria wrote in a Symantec security forum posting.

In its advisory, Microsoft noted that Windows Visa users are at less risk if they run IE 7 in Protected Mode, which isolates the browser from the rest of the operating system with different user privileges.

Microsoft also suggests workarounds in its advisory to help users protect themselves against the new issues. They include setting the Internet and Local security zone settings to "High," which will force the browser to prompt users before it runs any ActiveX controls from a Web site.

"Internet Explorer remote code execution vulnerabilities have very high impacts since the source of the malicious payload can be across any site on the Internet," Andre Protas, eEye's director of research and preview services, said in a statement. "An even more critical problem is generated when clients are administrators on their local hosts, which would run the malicious payload with Administrator credentials."

Microsoft has not yet publicly stated whether it will issue an out-of-cycle patch for the issue, and did not return requests for comment by press time.

However, in its advisory, Microsoft did indicate that a fix may be forthcoming in some capacity if the company decides it's necessary.

"On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through a service pack, our monthly security update release process, or an out-of-cycle security update, depending on customer needs."

News courtesy of internetnews.com

December 11, 2008

Download Internet Explorer Now!Download

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. New IE Flaw Emerges That Could Allow Remote Code Execution


Additional Articles:

  • Internet Explorer 7: Ready for Public Consumption
  • Gates Mixes It Up with IE, Atlas
  • Microsoft Plans Patch for IE Hole
  • New IE Exploits Create Security Scramble
  • IE 7 Is 'Layout Complete'
  • IE7 Beta 2 Out of Preview
  • Microsoft to Take Third Shot at IE 7 Beta
  • IE, Firefox Users at Risk from New Flaws
  • Third IE 7 Beta Has Layout Changes
  • First Release Candidate for IE 7 Hits
  • Report: IE 7 Has the Best Anti-Phishing Filter
  • Microsoft Planning Life After IE7
  • IE 7 Is Out the Door
  • IE 7's First Security Hole
  • Another Bug Bites IE7
  • Is IE 7 Limiting Remote Access SSL-VPNs?
  • IE 7 Tops 100M Download Mark
  • Internet Explorer at Zero-Day Risk
  • Microsoft Issues IE Security Alert
  • Microsoft to Roll Back the Clock on ActiveX
  • Internet Explorer 8 Passes the 'Acid2' Test
  • Internet Explorer 8 Tries New Compatibility Solution
  • IE8 Beta Soon But Few Details Yet
  • Microsoft Set to Fix IE Zero Day Flaw
  • Microsoft Patches IE, But Security Issues Remain
  • Hackers Target IE 7 Browser Again
  • EU to Insist Windows Includes Rival Web Browsers


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs