| Home > Security News > Triple trouble for Microsoft users | |
| Security News: |
|
||
Security researchers are warning of three new flaws attackers could exploit to compromise Windows machines, two of which affect Internet Explorer (IE) users. According to a series of advisories posted over the weekend: IE ActiveX flaw
"By convincing a user to view a specially crafted HTML document, an attacker may be able to execute arbitrary code with the privileges of the user," US-CERT said, adding that the attacker could also cause IE to crash. Until an official patch is released, US-CERT recommends users disable the ADODB.Connection ActiveX control in IE or disable ActiveX altogether. The Microsoft Security Response Center acknowledged in its blog that it is investigating the problem. "Once we have completed the investigation and understand if there is a threat to customers we will take the appropriate action to protect and provide guidance," Microsoft said. A third IE 7 glitch
The issue appears to be related to an older flaw reported nearly two years ago in earlier versions of the browser. Secunia's advice is to avoid untrusted Web sites. Last week, Secunia warned of another IE 7 flaw malicious people could exploit to launch phishing attacks. The week before, Secunia warned of another IE 7 flaw attackers could exploit to disclose sensitive information. Secunia said that flaw was caused by an error in how redirections for URLs with the "mhtml:" URI handler are processed. Christopher Budd of the Microsoft Security Response Center disputed Secunia's claims on that flaw, saying it is actually a flaw in Outlook Express. ICS flaw
"The exploit requires Internet Connection Sharing (ICS) to be enabled and requires that the attacker be on the shared interface," Reguly said. However, he added, the threat appears low. "Current research leads me to believe that this only affects Windows XP with ICS," he said. |
||||||||||||||||||||
|
|||||||||||||||||||||||||||
|
||||||||||