Quantcast

Critical Flaws Found in IE

Will Microsoft break its monthly patch cycle to fix the new holes?

Scarlet Pruitt, IDG News Service

  • 0 Yes
  • 0 No

A set of new security vulnerabilities have been discovered in Microsoft's Internet Explorer Web browser. If used together, these flaws could allow hackers to compromise user PCs, researchers warned Tuesday.

The five vulnerabilities have been reported in IE 6.0, although other versions may have been affected, according to a bulletin released by security company Secunia.

The scripting flaws could allow hackers to bypass security and compromise systems, giving them access to sensitive information and cross-site scripting, according to Secunia.

Critical Condition

The Copenhagen, Denmark, company has classified the vulnerabilities as "extremely critical" and is advising all IE users to disable Active Scripting or "use another product."

"If they care about Internet security, users should make sure to disable active scripting," Secunia Chief Technology Officer Thomas Kristensen said Wednesday.

Microsoft is currently investigating the new vulnerability reports but is not aware of any active exploits or customer impact at this time, according to a representative for Microsoft in the U.K.

Patch Process

Upon completion of its investigation, Microsoft may release a fix in its next monthly security update or an out-of-cycle fix if needed, the representative said.

However, Kristensen said he doubts that the software giant will break its monthly patch release cycle to address the issues.

"I would be happy to see them break their cycle because it affects customers, but I doubt it," he said.

The security flaws were originally discovered by Chinese security researcher Liu Die Yu, who published the vulnerabilities and proof of concept evidence Tuesday.

The Microsoft representative said that the company is "concerned that the new reports of vulnerabilities in IE were not disclosed responsibly, potentially putting computer users at risk."

The company advised users to download its latest IE cumulative patch, released November 11, while it looks into the new vulnerabilities.

  • Recommend this story?
  • 0 Yes
    0 No

Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.

Featured APC Accessories For Your System
10% Off Entire Cart at Online Store

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.

People who read this also read:

  • 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
  • Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.

PC World's Marketplace