02 Aug 2004
Microsoft has warned Internet Explorer users to patch their systems immediately after disclosing details of three new critical vulnerabilities in the web browser.
The software giant's MS04-025 security bulletin lists a Navigation Method Cross-Domain vulnerability, a Malformed BMP File Buffer Overrun vulnerability and a Malformed GIF Double Free vulnerability.
The existence of these vulnerabilities allows system exploitation by an attacker when a user is logged in as an administrator.
Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.
"If a user is logged on with administrative privileges, an attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system, including installing programs, viewing, changing, or deleting data, or creating new accounts with full privileges," Microsoft warned.
More information on the vulnerabilities can be found at the McAfee website here. Microsoft Security Bulletin MS04-025 and the relevant patches can be downloaded here.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Are you looking for a new positing within the Testing...
A leading global provider of critical information to...
Want to work for one of the most dynamic, creative environments...
Want to work for one of the most dynamic, creative environments...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?