Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

Reported IE 7 Bug Not in Browser

Microsoft says flaw is really a problem with Outlook Express.

Robert McMillan, IDG News Service

  • 0 Yes
  • 0 No

A flaw that research firm Secunia claimed to have discovered in Internet Explorer 7 just hours after its unveiling is not a browser bug after all, Microsoft said today.

Instead, the problem lies in a component of Microsoft's Outlook Express e-mail client, which can be triggered by the browser.

The flaw could be used in phishing attacks to read sensitive information from the IE browser, Secunia said. The Danish security firm first reported the problem with the IE 6 browser in April and found that it could be reproduced on IE 7 as well.

Secunia does not consider the problem to be critical, but it was widely reported because its discovery came so soon after IE 7's launch.

Not Accurate, Says Microsoft

"These reports are technically inaccurate," wrote Christopher Budd, a security program manager with Microsoft, in a blog posting. "The issue concerned in these reports is not in Internet Explorer 7 (or any other version) at all."

One security researcher said he was surprised that Microsoft had apparently not informed Secunia of the nature of this bug back in April, when it was first disclosed.

"They reported this in ... April," said Secure Network SRL Chief Technology Officer Stefano Zanero in an instant message interview. "Microsoft should have investigated then and should have already reported the bug to be not in IE."

"How was Secunia supposed to know?" he asked.

A spokesman with Microsoft's public relations agency could not say what response Microsoft had made to Secunia's first report of the problem back in April. "All I can tell you is that the ... blog is the latest and greatest information we have to share," he said.

  • Recommend this story?
  • 0 Yes
    0 No

"Reported IE 7 Bug Not in Browser" Comments

  • Great year-end deals for small business!
  • Get 24/7 live remote AT&T Tech Support 360* service along with select Lenovo* PCs (with Intel® Core™ 2 Duo processors and save up to 200!

    Learn more

  • HP EliteBook* 6930p Notebook with Intel® vPro™ technology and a free HP Basic Docking Station - $641 instant savings!

    Learn more

Dell Fast Track

People who read this also read:

  • 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
  • A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.

Sponsored Links