IE open to hackers
IE open to hackers

IE plagued by 'extremely critical' flaws

Security firm advises get another browser

Iain Thomson

Millions of Internet Explorer 6 users are at risk from three "extremely critical" security holes that give hackers open access to PCs running the browser - even if Windows XP Service Pack Two has been installed.

The first issue centres on the browser's drag and drop capability, which does not validate new files correctly. This means that, potentially, a document downloaded from a web page using drag and drop may contain malicious code.

Advertisement

The other problems affect all Windows systems, including those protected by Local Computer zone lockdown that comes with SP2. The first allows specially designed (.hhk) files to be used to include malicious code on systems and the second stems from a zone restriction error that could allow code to be downloaded form web sites involuntarily.

At least one of the flaws was reported to Microsoft last year but no patches have so far been made available.

Security firm Secunia has released an advisory warning that the holes are "extremely critical" and recommends users dump IE and use an alternative browser.

"

Although hundreds of millions of dollars have been spent on securing SP2, perfection is impossible. Through the joint effort of Michael Evanchik and Paul from Greyhats Security a very critical vulnerability has been developed that can compromise a user's system without the need for user interaction besides visiting the malicious page," Secunia warned in a statement.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

Samsung talks up 3D TV

The next big thing, but it will take some time

Views from the Valley, 9 March 2010

Batteries, browsers and recognition for PARC researchers

Analysis and Reports

Continuous Availability for Microsoft SharePoint

This paper examines how to create continuous availability for Microsoft SharePoint by implementing high availability and disaster recovery solutions.

Database security: Preventing enterprise data leaks at the source

This report looks at the challenge of information protection and control (IPC) and how enterprises must adopt database security best practices

Poll

International Women’s Day poll

International Women’s Day poll

Have measures to encourage women into the IT profession been successful?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

SXSW Interactive

Mobile location services set for mainstream uptake

Social sites to showcase new offerings at SXSW Interactive

Opera

Opera launches Mini 5 for Android smartphones

Firm promises fastest speeds for Google platform

Eugene Kaspersky

Kaspersky calls for international internet government

Kaspersky Lab co-founder argues for multinational body to tackle cyber...

Parliament

Digital Economy Bill may escape Commons scrutiny

Government copyright proposals head for the 'wash ups'

Primary Navigation