All the latest UK technology news, reviews and analysis

HTML bug hits Internet Explorer

by James Middleton

12 Apr 2001

Be the first to comment

  • Tweet this

Security firms today revealed a "high risk bug" which sneaks malicious code onto a machine running Microsoft Internet Explorer (IE).

This latest vulnerability, which comes only a week after the uncovering of a separate flaw affecting IE's mail extenstions, centres on HTML-based emails.

HTML mails, which are effectively websites, could potentially run an embedded file attachment containing malicious code if a user previews the code using Outlook. The user would not even have to open the message to activate the code, according to security firm GFI.

The vulnerability is carried out through the use of an HTML content tag known as IFrame which is used to embed another frame, or web page, inside the main one. The embedded page would be responsible for loading or activating the malicious code.

GFI's chief executive Nick Galea told vnunet.com that Microsoft has released a patch to fix the vulnerability, available here, but added that filtering email at server level to remove potentially dangerous code such as the IFrame tag was the best way to combat the threat.

"HTML mail viruses are becoming more sophisticated and more difficult to detect and stop," said Galea. "The recently discovered vulnerability is a clear example of how dangerous HTML mail scripting can be. Exploits like this indicate that other such HTML viruses lie close ahead."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

C# DEVELOPER- Commodities Index Trading

A senior C# developer is required by a leading investment...

SENIOR JAVA/ J2EE DEVELOPER

A senior JAVA developer is required by a leading financial...

AGILE JAVA DEVELOPER- INVESTMENT BANKING

A leading investment bank are looking for an AGILE JAVA...

C# WPF F# developer- Quant group

A senior C# WPF F# developer is required by a leading...

To send to more than one email address, simply separate each address with a comma.