Quantcast
RSS
Erik Larkin on the Web
Fresh news, links, and opinion for your business | Read intro... » More Erik Larkin on the Web » RSS » All Blogs

Microsoft Warns Against Using Safari

Microsoft on Friday warned of a serious risk to people who use Safari on Windows XP or Vista, going so far as to suggest people "restrict use of Safari as a web browser until an appropriate update is available from Microsoft and/or Apple."

Good news is that according to Redmond there aren't yet any known attacks against the flaw.  Bad news is that if anyone does create such an attack, a crook could install any software he wished - such as 'bot' malware that allows for complete remote control - on a victim PC.

The threat targets two separate flaws, one in Safari and one in IE, and you'd have to first browse a malicious site with Safari. Doing so would download unwanted software onto your desktop, which could then be executed without your permission by triggering a separate flaw in IE (and you wouldn't have to start IE to get hit).  In its security advisory, Microsoft acknowledges the critical risk of 'remote code execution,' which is as bad as it gets. 

Apple, on the other hand, says "we are not treating this as a security issue," according to a quoted e-mail posted by stopbadware.org.  Not a good move, if you ask me.

If you do use Safari, Microsoft says you can apply a workaround to protect yourself. Change the default download location (normally the desktop) in Safari with the following steps:

Launch Safari. Under the Edit menu select Preferences.

At the option where it states Save Downloaded Files to:, select a different location on the local drive.

For more information on the hole, see "Safari Flaw Worse Than First Thought, Microsoft Warns," from the IDG News Service's Robert McMillan.

Was this article useful? Yes 0 No 0
Add Yours

Comments Readers reply with their ideas and expertise.

Subscribe to this discussion via email or RSS
  • What do you think?

  • Great year-end deals
    for small business!
  • Get 24/7 live remote AT&T Tech Support 360* service along with select Lenovo* PCs (with Intel® Core™ 2 Duo processors) and save up to 200!

    Learn more

  • HP EliteBook* 6930p Notebook with Intel® vPro™ technology and a free HP Basic Docking Station - $641 instant savings!

    Learn more

Business News Daily

Get the latest technology news that's important to you and your business, fresh seven days a week.

Featured Webcasts

Free Whitepapers

Software and Services Whitepapers from PC World

More whitepapers »

Whitepaper Alerts

Get updates on white papers, case studies, and spotlights on tech products and solutions for your business.

PC World's Marketplace

Sponsored Links