Users login

Create an account »

JOIN XATRIX

Users login

Home » Hacking News » IE subject to unpached vulnerabilities

IE subject to unpached vulnerabilities

by Nikola Strahija on November 24th, 2004 A security firm called Secunia warned yesterday that IE is subject to a trio of unpatched vulnerabilities. It warns that two of the three unfixed security bugs are on the "critical" list.


These two could be exploited in tandem to bypass security features in Windows XP SP2 and trick users into downloading malicious files. Flaws in the function used to warn users that they are downloading a potentially executable file and a separate bug that can be used to spoof the file extension in the "Save HTML Document" dialog give attackers the opportunity to disguise malicious executable files as innocent HTML documents.

The vulnerabilities have been confirmed on a fully patched system with IE 6.0 and Windows XP SP2. Secunia advises IE users to Disable Active Scripting support and the "Hide extension for known file types" option. Secunia describes the flaws as "moderately critical".

A third - less serious - IE bug that could be used to overwrite cookies from trusted site has also been discovered. The vuln has been reported in Internet Explorer 6.0 SP1 on Microsoft Windows XP SP1. But Windows XP SP2 is reportedly immune to the exploit, which in any case only works if a trusted site handles cookies and authentication badly.


Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.

Contact

Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »