All the latest UK technology news, reviews and analysis

Microsoft issues zero-day IE warning

by Dave Neal

24 Nov 2009

Be the first to comment

  • Tweet this
Microsoft bugs
The IE flaw could allow hackers to run malicious code

Microsoft has issued a security advisory for a zero-day Internet Explorer vulnerability that emerged yesterday.

The advisory was released late last night, and confirms that Microsoft is investigating the issue. Security experts had warned that the flaw could cause the browser to crash or take the user to an infected web page.

Microsoft has now issued information about the affected IE versions, and the appropriate workarounds.

IE6 Service Pack 1 on Windows 2000 SP4, and IE6 and IE7 on supported editions of Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008 are all affected. IE5.01 Service Pack 4 and IE8 on all supported versions of Windows are not affected.

Microsoft also confirmed that the vulnerability could allow CSS/Style object attacks, which could run malicious code possibly leading to remote control and the taking over of local user rights.

"On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs," the advisory said.

In the meantime Microsoft urged all users to make sure that their applications, firewall and anti-virus systems are up to date.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

28%

2%

13%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

.NET C# Dynamics CRM SQL Server Developer - Banking

C# Developer with MS Dynamics A global Bank is currently...

IT Systems Management Team Leader

CCNA accredited IT Systems Management Team Leader required...

Oracle DBA

Oracle Administrator (Oracle Agile PLM DBA) Title...

J2Me Mobile Developer

J2ME Mobile developer required to work in Yorkshire...

To send to more than one email address, simply separate each address with a comma.