All the latest UK technology news, reviews and analysis

Warning issued on new IE flaws

by Iain Thomson

More from this author

14 Jun 2004

Be the first to comment

  • Tweet this

Three new flaws for which no patch exists - so-called 'Zero Day' flaws - have been identified in Microsoft's Internet Explorer.

Like Sasser, two of the three vulnerabilities need no user intervention and can be downloaded just by logging on to the internet.

The third allows a false web address to be embedded in an email to misdirect users to a phishing site, which then attempts to capture user information.

The US Computer Emergency Readiness Team warned of the phishing flaw late on Friday, while security firm Ubizen highlighted the other two after being in contact with a researcher investigating computers where pornographic banners had been inserted into the browser toolbar.

Ubizen has advised computer users to switch to alternative web browsers like Netscape or Mozilla for the moment.

"[Changing browser is] a harsh workaround but at the end of the day it'll work," said Dick Van Droogenbroeck, senior security assessment engineer at Ubizen's Security Intelligence Laboratory.

"As there is no fix available, the hacker community will seek to massively exploit these vulnerabilities. Hit the wrong web page and it's over and out."

No patches are available as yet.

In a statement, Microsoft said: "Microsoft is actively investigating these reports, to determine the appropriate course of action to protect our customers. This might include providing a fix through our monthly release process or an out-of-cycle security update, depending on customer needs.

The software giant also promised to "work aggressively with law enforcement to help prosecute individuals or organisations" who exploit the flaws.

Microsoft urged customers to review its safe browsing tips. Details of how to strengthen browser security are also available here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Information Security Manager

My client is a well established, non profit organisation;...

PHP Web Developer

PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...

HEAD OF DIGITAL - London - £80-95K+

HEAD OF DIGITAL - London - £80-95K + Excellent Bens...

Agile C# Developer - (North London)

Agile C# Developer - (North London) £55,000 - £65,000...

To send to more than one email address, simply separate each address with a comma.