internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Opera
Internet Explorer 7
QuickTime for Windows
Winamp
Mozilla Firefox 3
Ad-Aware 2008 Free
Adobe Flash Player
Paint Shop Pro
Adobe Shockwave Player
AVG Anti-Virus Free
7-Zip

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Unpatched IE Flaw Now Exploitable
PoC Code Posted for Extremely Critical IE Vulnerability
Sean Michael Kerner

Proof of Concept (PoC) code has now been publicly released for a flaw in Internet Explorer that Secunia rated "extremely critical." It is potentially leaving untold millions of Microsoft Internet Explorer users at risk.

The Microsoft Internet Explorer JavaScript window() DoS vulnerability was originally reported at the end of May.

The flaw could potentially allow a malicious remote user to trigger a DoS by way of a JavaScript onload event that calls the window function.

"Contrary to popular beliefs, the aforementioned security issue is susceptible to remote, arbitrary code execution, yielding full system access with the privileges of the underlying user," according to security firm, Computer Terrorism.

To back up its point and ultimately put millions of users at risk of attack, Computer Terrorism has posted proof of concept code that demonstrates how easy it is to compromise a fully patched IE user's PC.

Johannes Ullrich of the SANS Internet Storm Center (ISC) noted that the flaw allows for arbitrary executables to be executed without user interaction.

Computer Terrorism's PoC demo will launch a calculator (calc.exe), though Ullrich commented that there is also a version that will allow a user to open a remote shell.

As a result of the publicly available PoC, security news aggregator Secunia has upped its assessment of the flaw to extremely critical, its highest security warning level.

IE users are being advised to disable JavaScript on non-trusted sites until a patch is released.

A Microsoft spokesperson confirmed that the company is aware of new public reports of a possible vulnerability in IE for customers running Windows 2000 SP4 and Windows XP SP2.

According to the spokesperson, customers running Windows Server 2003 and Windows Server 2003 SP1 in their default configurations, with the Enhanced Security Configuration turned on, are not affected.

"We have also been made aware of proof of concept code that could seek to exploit the reported vulnerability, but are not aware of any customer impact at this time," the spokesperson said. "But Microsoft will continue investigating these public reports."

Once the investigation is completed, the spokesperson said that Microsoft will take the appropriate action to protect its customers, which may include providing a fix through its monthly release process or issuing a security advisory, depending on customer needs.

News courtesy of internetnews.com

November 22, 2005

Download Internet Explorer Security Patches Now!Download

View All Microsoft Service & Security Releases

Contents:
1. PoC Code Posted for Extremely Critical IE Vulnerability


Additional Articles:

  • Malware Hacker Attack Linked to Spammers
  • Malware Attack Thwarted, But Danger Lurks
  • US Gov: Beware of IE
  • Microsoft Issues Security Update for Trojan
  • Another IE Flaw in the Wild?
  • Microsoft Faces Angry IE Users' Questions
  • Microsoft Releases New Tool to Zap Download.Ject
  • Microsoft: Out-of-Cycle Security Patch Coming
  • 'Critical' IE Patch Released
  • MS Patch Barrage Comes with IE Fix
  • 'Drag-and-Drop' IE Flaw Persists
  • MS Patches IFRAME Vulnerability Out of Cycle
  • Microsoft Patches Three Holes, Offers Removal Tool
  • Microsoft Patch Day Plugs 3
  • Microsoft Patches 3 Critical Flaws
  • IE Workarounds for New Zero Day Exploit
  • Microsoft Going Critical on Tuesday
  • Microsoft Crafts Critical Patches
  • Microsoft Warns on Windows, IE Flaws
  • Microsoft Patches IE, Windows, Office
  • Microsoft's Patch of a Patch Will Be Late
  • Latest IE Zero Day Has XML Designs
  • IE Vulnerability Spreads to Email
  • IE VML Exploit Growing in Severity
  • VML Exploit Patched, Questions Remain
  • PowerPoint, IE Hit by New Zero-Day Flaws




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers