A new vulnerability in the way Internet Explorer deals with Macromedia Flash files could leave users open to phishing attacks
Hackers could exploit an IE flaw to spoof the address bar in a browser window

Phishers catch Internet Explorer again

Flash files a bit too flash, it seems

Matt Chapman

A new vulnerability in the way Internet Explorer deals with Macromedia Flash files could leave users open to phishing attacks. 

The vulnerability was discovered by a user called Hai Nam Luke and posted on security firm Secunia's list of advisories

Advertisement

The problem is caused by a 'race condition' in the loading of web content and Macromedia .swf files in browser windows.

Malicious users could exploit this to spoof the address bar in a browser window that displays a Flash file from a malicious website. Secunia ranked the problem as 'moderately critical'.

"The impact of exploitation is reduced because the URL of the malicious Flash file is visible in the title of the browser window," said the security firm in a statement.

The vulnerability has been confirmed on a fully patched system running Internet Explorer 6.0 and Microsoft Windows XP with Service Pack 1 and 2.

Secunia said that other versions of the operating system and browser may also be affected.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

EEye has engineered the patch to automatically remove itself when Microsoft's official patch comes through

Security firm plugs Internet Explorer hole

Workaround promises to protect browser in anticipation of official fix

Two of the bugs could allow remote code to be run on the user's PC

Microsoft hints at early IE bug fix

Internet Explorer problems may be fixed before the next update

Attackers target unpatched IE bug

Zero day attack hits the web

Internet Explorer bombarded by bugs

Microsoft admits three new vulnerabilities in as many days

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

old computer

Government honours veterans of Bletchley Park at last

Surviving veterans of the code-breaking facility to receive badge of...

Motorola MC55 Enterprise Digital Assistant

Review: Motorola MC55 Enterprise Digital Assistant

A rugged Windows Mobile device for mobile workers

BT

BT promises 1.5m fibre connections by summer 2010

Telco begins major rollout in 69 locations across the UK

Primary Navigation