On BNET: Sneak peek at Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto
Posted on ZDNet News: Sep 6, 2005 7:33:00 PM

A security flaw has been found in the default installation process for Microsoft's Internet Explorer, Outlook and Outlook Express, according to eEye Digital Security.

A common thread with these applications is the potential for a buffer overflow, which in turn could allow an attacker to gain access to users' systems remotely, said Mike Puterbaugh, eEye's senior director of product marketing.

eEye, which issued an announcement about the problem late last week, noted that systems at risk include those running Windows XP with Service Pack 0 or 1 and Windows 2000. The security specialist noted that it is still conducting reviews of the flaw and could find that other versions of the operating system are affected.

Microsoft is unaware of any attacks involving the reported vulnerability or any customers who have been affected, a company representative said.

The vulnerability is only the latest IE security flaw researchers have discovered since Microsoft released a cumulative update for the browser last month, Puterbaugh said. Other flaws reported in the past few weeks range from a vulnerability with version 6 of the browser on Windows XP with Service Pack 2 to an IE flaw involving the Microsoft DDS Library Shape Control file.

"I wouldn't be surprised to see Microsoft release another cumulative update for IE in the near future," Puterbaugh said.

While eEye has provided Microsoft details on the vulnerability it found, the security researcher does not provide the public with such details until after a vendor has developed a relevant patch or issued an advisory.

"Microsoft is aggressively investigating these reports," the software giant's representative said. "Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers."

Currently, eEye is readying 12 vulnerability advisories for publication after patches or workarounds are released by vendors. Of these, nine are related to Microsoft.

  • Talkback
  • Most Recent of 83 Talkback(s)
Lack of a monopoly.
Having a monopoly definitely makes a difference. Don't take my
word for it. Just look at how Microsoft has lied, cheated, begged,
pleaded bribed and whined to hold on to the one it's got. If i... (Read the rest)
Posted by: Immanuel Tranz-Mischen Posted on: 09/14/05 You are currently: Logged In as: a Guest  | Login | Terms of Use
Service Pack Zero?  voska | 09/06/05
you caught that too lol  linuxoverwindows | 09/06/05
Perhaps it means the beta version ?? (NT)  George Jay | 09/07/05
Beta XP ???  dcollins@... | 09/10/05
odd alright  waylander | 09/07/05
correct  ibn4n | 09/07/05
A flaw in a windows component? Say it ain't so!  JonathonDoe | 09/06/05
OMGOMGOMG!@  Loverock Davidson | 09/06/05
OMGOMGOMG!@ ...  dshans@... | 09/06/05
A flaw in a windows component? Say it ain't so!  a_spicer@... | 09/06/05
not me  linuxoverwindows | 09/06/05
RE: not me  nightshade0143 | 09/07/05
Windows users tucked again  Rick_K | 09/06/05
Hmm...Doen'st Fee Like Abused...  GuyAlanDye | 09/06/05
That Would Be "Doesn't Feel Like Abuse"...  GuyAlanDye | 09/06/05
Have you ever heard of "Stockholm Syndrome"?  tic swayback | 09/06/05
Dump  MIS Master | 09/06/05
lmao youre funny  linuxoverwindows | 09/06/05
Windows users tucked again  a_spicer@... | 09/06/05
Outlook Express  Kajoe | 09/06/05
POP3 redirect  SupraGuy | 09/06/05
Some Firewalls will also  Confused by religion | 09/06/05
Outlook Express  a_spicer@... | 09/06/05
Server IP Address  jrmtay@... | 09/06/05
antivirus and antispam crap  linuxoverwindows | 09/06/05
Too busy to update???  poppajohn | 09/06/05
I'm way too busy  tic swayback | 09/06/05
Me too  slingzenarrowzuvowtrayjissforchin | 09/06/05
Me too  a_spicer@... | 09/06/05
Still immune from "all those viruses"  tic swayback | 09/06/05
its only because nobody cares bout your 2.1 % share of the desktop market  waylander | 09/07/05
And your point is?  vince@... | 09/07/05
Works for me  tic swayback | 09/07/05
Thank goodness I'm immune too  NonZealot | 09/07/05
Good for you  tic swayback | 09/07/05
I'm way too busy  a_spicer@... | 09/06/05
Yes, let's wait till that happens  tic swayback | 09/07/05
Just in case it happens...  Immanuel Tranz-Mischen | 09/14/05
some of us, yes.  linuxoverwindows | 09/06/05
Well....  Wolfie2K3 | 09/06/05
kinda  ibn4n | 09/07/05
XPe  mischief_z | 09/07/05
According to what I've heard  lengua99 | 09/11/05
So tell me poppa  Taz_z | 09/07/05
New IE/OE flaws found? Is it Tuesday? nt  michael_t | 09/06/05
Flaw IE,Outlook  fsh4fun | 09/06/05
Why should we care? Oh, that's right, it's integrated with Windows! (nt)  CobraA1 | 09/06/05
Why is this headlines?  joejett1115@... | 09/06/05
Why is this headlines?  a_spicer@... | 09/06/05
Another leak in the boat?!  Andromedat6 | 09/06/05
FLAW?  UvGottaBKidding | 09/06/05
thats how we roll  linuxoverwindows | 09/06/05
I'MA JOKER  djteel2005 | 09/06/05
Same conversation different day  Windoze Is For Lusers | 09/06/05
why we gotta be n00bs?  linuxoverwindows | 09/06/05
Pfft  Mike2575 | 09/06/05
I'm Tired and Weary of carrying this load  duclod | 09/06/05
So join the "Boston Tea Party" and throw it overboard!  Zogg | 09/07/05
Flaws Flows and more Flaws  ugetme247@... | 09/06/05
flipper did it on porpoise  djteel2005 | 09/06/05
MS has a halibut of creating crappie software  MacCanuck | 09/07/05
Another week...  Dave P. | 09/07/05
First time internet connection resulted in IE going blank  palmtree | 09/07/05
Yeah, why are we noobs?  Chad_z | 09/07/05
RE: Yeah, why are we noobs?  node357 | 09/07/05
n00bs and Windows  DragonBRockin | 09/07/05
Oh, please do it...  furballtipster | 09/07/05
eEye -- hmmm...  rtrent@... | 09/07/05
Why Do We Call These Things Flaws??  charlesgoff | 09/07/05
RIGHT ON!!!  DragonBRockin | 09/07/05
Same reason MS pushes a fix  zen_dogen | 09/07/05
Mega$#|+ just trying to extort more  btljooz | 09/07/05
Aren’t you crazy?  furballtipster | 09/07/05
But they fix it for free.  dgari | 09/07/05
The Ninth Wave  Canario_z | 09/07/05
WhiteBox your own Mac, using the intel move  BuckRogers_z | 09/07/05
This will not happen, until  furballtipster | 09/07/05
Ease of use?!  Andromedat6 | 09/07/05
So,  furballtipster | 09/08/05
Lack of a monopoly.  Immanuel Tranz-Mischen | 09/14/05
Not to mention...  Immanuel Tranz-Mischen | 09/14/05
Security flaws in Windows  SilverEagle_z | 09/07/05
This called  furballtipster | 09/08/05

What do you think?

advertisement
advertisement
advertisement
Click Here