Leaked Windows Code Opens IE Hole
Bug hunters use source code to identify flaw in widely-used browser.
Joris Evers, IDG News Service
A bug hunter claims to have uncovered a security flaw in Microsoft's Internet Explorer 5 Web browser by studying Windows source code that was leaked last week.
The vulnerability allows an attacker gain control over a user's computer by using a specially crafted bitmap file. When loaded using IE 5, the file will trigger an overflow error and allow the attacker to run arbitrary code on a victim's machine, according to a description of the flaw posted Sunday on the SecurityTracker.com Web site.
The flaw was uncovered by reviewing IE source code that was part of a larger Windows code leak last week and exists in all versions of IE 5 for all Windows versions, according to the description.
World Wide Web
Vulnerable versions of IE are used by millions of Internet users. As of February 16, 17 percent of Internet users worldwide had some version of IE 5 installed, according to San Diego-based Web tracking company WebSideStory.
Thor Larholm, senior security researcher at PivX Solutions in Newport Beach, California, confirms the vulnerability. He investigated the report and tested code to exploit the flaw.
The IE 5 problem proves the security implications of the code leak, where a malicious coder could take advantage of the source code to find security holes, Larholm says. "This has definitely proven the potential for critical vulnerabilities," he says.
Microsoft began investigating the vulnerability report on Monday, the company says in a statement. The security problem is a known issue that the Redmond, Washington-based vendor discovered internally before and fixed in IE 6.0, according to the statement.
Upgrade Available
Microsoft urges IE 5 users to upgrade to IE 6.0 with Service Pack 1. However, IE 5.01 with Service Pack 2 is still supported, according to Microsoft's product support Web page. The vendor is working on a patch for this and other versions of IE predating IE 6.0 and is investigating why it did not fix the vulnerability in those versions before, a Microsoft spokesperson says Tuesday.
Microsoft last week said that incomplete portions of its closely-guarded Windows NT and Windows 2000 source code, the blueprints of the operating system software, had been leaked on the Internet.
Analysts and security experts at the time warned that a breach of the Windows source code could expose users to an increase in cyberattacks because it would make it easier for hackers to find holes in the operating systems that they could exploit.
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
PCW Download Guide
PCW's Mobile Life Guide
Related Browsers & Add-Ons Articles
- Use Gmail to Fight Spam Gmail already offers champion spam-filtering for Gmail accounts. Here's how to leverage it with non-Gmail accounts.
- Sync 'Em 1.00 Released Derman Enterprises has announced the release of Sync 'Em 1.00, a new "sync hub" for Mac OS X. It costs US$14.95 for a license...
- Favorite Firefox Extensions One of the big advantages Firefox 3 holds over Safari is extensibility. Savvy users can customize the browser to look, feel...
- VideoPier Simplifies MPEG-2/AVCHD Camcorder Use Aquafadas has announced the release of VideoPier and VideoPier HD, two new utilities designed to help users of camcorders that...
- Newsstand and News Now for IPhone Old rituals wither and die; new rituals crop up and replace the old. When I used to work on the west side of Los Angeles, one...
Best Prices on Security Software
Norton Internet Security 2008Price: $13.98
Internet Security 2008 - 3-User (Full Product, PC)Price: $11.49
Norton 360 2.0 ( PC)Price: $44.99
Kaspersky Internet Security 2009Price: $25.95
Norton Internet Security 2009Price: $25.49
Internet Security Suite 2008 - 3-UserPrice: $14.95
- Web Demo: Discover the Benefits of VoIP Is your company looking for a world class VoIP communications solution that will meet all of your business requirements? If so, join us for our Live Online Demo where you will receive a "guided tour" to the AltiGen Solution.
- PC World Webcast: Going Green Wondering how to make your business greener? These tips will help your business save money, and save the environment.
- A Windows Vista FAQ Corporate customers are deploying Windows Vista now, and Dell Services wants to help you understand the features of the new OS and how to plan your Windows Vista deployment.



