Microsoft Upgrades Warning on IE Flaw
Users urged to patch security hole now considered 'critical.'
Joris Evers, IDG News Service
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
For the second time in December, Microsoft is raising the risk rating on a flaw affecting Internet Explorer after experts told the company it underrated the issue.
The cumulative patch announced on November 20 in Microsoft's security bulletin MS02-066 for the IE Web browser will now be rated "critical," up from "important," according to Steve Lipner, director of security assurance at Microsoft.
Ongoing Concern
Microsoft initially thought a buffer overrun that results when PNG (Portable Network Graphics) files are opened could only be exploited to cause IE, Microsoft Office applications, or the Microsoft Index Server to fail. Now Microsoft warns that successful exploitation of the flaw could allow an attacker to gain control over a user's machine.
Security vendor Eeye Digital Security, the discoverers of the PNG vulnerability, earlier this week said the flaw should get the highest risk rating, as it allowed an attacker to run code on a victim's PC. As a result, Microsoft is raising the severity rating of bulletin MS02-066, although it has not yet been able to verify the exploit, Lipner said.
Buffer overrun flaws generally allow an attacker to take over a user's machine. An attacker exploits an unchecked buffer in a program to load his own code onto a system and run it.
This is the second time this month that Microsoft has been forced to increase the severity rating on a security vulnerability affecting IE, the Web browser used by millions worldwide. Last week, Microsoft increased from "moderate" to "critical" the rating on a flaw in an IE security feature discovered by GreyMagic Software of Israel.
After reexamining that issue, Microsoft said it found a new exploit scenario that could allow a malicious user to run code on a user's computer via a specially crafted Web site or e-mail message, warranting a severity rating of critical, it said.
New Warning System
Under Microsoft's security rating system, changed in November, critical vulnerabilities are those that could be exploited to allow Internet worms to spread without user action. Vulnerabilities rated "important" are those that could expose user data or threaten system resources. The two other ratings are "moderate" and "low" and are given depending on how difficult it is to exploit a flaw.
"We are continuing to review our processes for reproducing reported vulnerabilities, and for working with external security researchers to ensure that our severity ratings are as accurate as possible," Lipner said.
The cumulative patch announced in MS02-066 provided all previously released fixes for IE 5.01, IE 5.5, and IE 6 and patched six other new vulnerabilities. To exploit the PNG vulnerability, an attacker would have to lure a user to a Web site hosting a deliberately malformed PNG file, Microsoft said. According to eEye, an e-mail-based attack is also possible.
The patch announced in bulletin MS02-066 does eliminate the vulnerability. Microsoft notes that users should no longer install this cumulative patch, as it has been superseded by a new one. The latest super patch for IE, which includes all previously released patches, was announced in bulletin MS02-068 on December 4 and is rated critical.
"We strongly encourage customers to apply the patch for MS02-068," Lipner said.
PCW Download Guide
CDW Virtualization Center
Related Browsers & Add-Ons Articles
- Quick Fix for Firefox 3 Bug with Yahoo Mail If you're missing scrollbars in Yahoo Mail, here's how to get them back.
- Apple: Forget ICards, Try Mail This June's Worldwide Developers Conference saw Apple unveil the iPhone 3G, firm up its iPhone 2.0 plans, offer a brief peek...
- Ease the Safari-to-iTunes Lyric Pasting Task If you enjoy having lyrics with your music in iTunes, you're probably familiar with the tools available to collect those...
- Bugs & Fixes: ITunes' CD Mounting Bug Most often, when Apple releases an minor update to one of its applications, such as iTunes, its purpose is to provide bug...
- Yelp for IPhone You'd be hard pressed to find a more opinionated, verbose, and downright catty group than the citizen reviewers on...
Best Prices on Security Software
Norton Internet Security 2008Price: $19.40
Internet Security 2008 - 3-User (Full Product, PC)Price: $12.99
Norton 360Price: $32.99
Norton 360 2.0 ( PC)Price: $40.00
Internet Security Suite 2008 - 3-UserPrice: $18.95
Internet Security 7.0 - 3-UsersPrice: $19.95
- PC World Webcast: Going Green Wondering how to make your business greener? These tips will help your business save money, and save the environment.
- The Future Sales Force - A Consultative Approach This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ in today's evolving market.




