Brief: IE Harbors Yet Another Bug - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
News
News
9/28/2006
04:53 PM
50%
50%

Brief: IE Harbors Yet Another Bug

The flaw is in an ActiveX control included with Windows 2000, Windows XP, and Windows Server and can be exploited to overflow Internet Explorer's buffer, then introduce malicious code to the compromised PC.

A working exploit against yet another unpatched bug in Internet Explorer has popped up, security researchers, including those at US-CERT, said Thursday.

The flaw is in an ActiveX control included with Windows 2000, Windows XP, and Windows Server, said Symantec. As with another still-unfixed vulnerability disclosed two weeks ago, the control -- WebViewFolderIcon -- can be exploited to overflow Internet Explorer's buffer, then introduce malicious code to the compromised PC. US-CERT, the federal cyber-alert agency, also issued a warning.

HD Moore of Metasploit first reported the vulnerability in July as part of his "Month of Browser Bug" project. Then, however, Moore's proof-of-concept code only demonstrated a denial-of-service that crashed the browser.

"Now that a functional exploit is available, an official patch from Microsoft will likely appear at some point in the future," Symantec said in an alert to customers.

That may be whistling in the dark, however, since Microsoft has several outstanding vulnerabilities to contend with, including the earlier ActiveX flaw and one publicized Wednesday in Microsoft Office's presentation software, PowerPoint.

Microsoft has not posted an advisory for the new flaw, and Symantec and US-CERT only suggested that users either disable Active Scripting in IE or set the "kill bit" for the ActiveX control. The latter, however, is somewhat technical and if done incorrectly, can damage the operating system.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
2020 State of DevOps Report
2020 State of DevOps Report
Download this report today to learn more about the key tools and technologies being utilized, and how organizations deal with the cultural and process changes that DevOps brings. The report also examines the barriers organizations face, as well as the rewards from DevOps including faster application delivery, higher quality products, and quicker recovery from errors in production.
News
Think Like a Chief Innovation Officer and Get Work Done
Joao-Pierre S. Ruth, Senior Writer,  10/13/2020
Slideshows
10 Trends Accelerating Edge Computing
Cynthia Harvey, Freelance Journalist, InformationWeek,  10/8/2020
News
Northwestern Mutual CIO: Riding Out the Pandemic
Jessica Davis, Senior Editor, Enterprise Apps,  10/7/2020
Register for InformationWeek Newsletters
Video
Current Issue
[Special Report] Edge Computing: An IT Platform for the New Enterprise
Edge computing is poised to make a major splash within the next generation of corporate IT architectures. Here's what you need to know!
White Papers
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll