On CNET: Keep your software up-to-date
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Aug 30, 2005 5:30:00 AM

A new, unpatched flaw in Internet Explorer could let miscreants surreptitiously run malicious code on Windows PCs, according to the discoverer of the bug.

The problem affects Internet Explorer 6--the latest version of Microsoft's Web browser--on computers running Windows XP with Service Pack 2 and all security patches installed, Tom Ferris, an independent security researcher in Mission Viejo, Calif., said in an interview Monday. Other versions of Windows and IE may also be vulnerable, he said.

The security hole allows for "full-blown remote code execution," Ferris said. "If a user browses to a bad Web site, malicious software can be installed on their PC without their knowledge."

Ferris claims credit for discovering the problem and said he informed Microsoft of the flaw on Aug. 14. He reported some basics of the bug on his Security Protocols Web site Saturday, but he is not sharing more details to prevent information from getting into the wrong hands.

A Microsoft representative late Monday confirmed the company received Ferris' report. The Redmond, Wash., software giant can't confirm whether the flaw exists, but it is investigating the report, the representative said. "At this time, there are not any attacks, and there are not any risks" to users, she said.

Ferris said he provided Microsoft with details on the bug, including computer code to prove the existence of the problem. On his Web site, Ferris shows a screen shot of a crashing IE 6 Web browser, which he said was caused by the same bug.

Upon completion of the investigation, Microsoft will take the appropriate action to protect users, the representative said. This may include providing a security update through its monthly patch release or providing an out-of-cycle security update, she said.

There are several unpatched vulnerabilities in IE 6, according to Secunia. The security monitoring company has issued 69 alerts on the Web browser since 2003; almost one-third of those security bugs remain unpatched, according to Secunia's Web site. Secunia has yet to put out an advisory on this latest IE security issue.

Ferris has found bugs in Microsoft software before. Earlier this month, Microsoft credited him with reporting a bug in a Windows feature called the Remote Desktop Protocol that could allow an attacker to remotely restart Windows systems.

Ferris recommends people pick a different Web browser or use caution when surfing the Web to protect against any exploitation of the latest IE flaw and other browser bugs. Microsoft, as always, urges users to apply all available software patches and run updated security software.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 96 Talkback(s)
find a flaw , fix a flaw
if you have the time to find these flaws .which i think is admerable.why not take the time to fix the flaw and sell it for a buck or two. if its legal,it would more then pay for your time.not to mention the pressure it would put on the manufactures to update there products in a timly manner.... (Read the rest)
Posted by: johni123 Posted on: 09/13/05 You are currently: a Guest | | Terms of Use
security hole of the week...........  Andromedat6 | 08/30/05
RE: "security hole of the week..........."  ajapierce | 08/30/05
mmmmmmm  mujadaddy | 08/31/05
Try a mac as a second computer.  trm1945 | 08/30/05
Second Computer?  Otto_Delete | 08/30/05
Mac as second computer  SilverEagle_z | 08/30/05
Correction Primary computer!  An_Axe_to_Grind | 08/31/05
Confused  BXLE | 08/30/05
The Why...  Wolfie2K3 | 08/30/05
Hey!  mujadaddy | 08/31/05
When we leave the home, do we lock the door?  emi1999@... | 08/30/05
The answer ...  whisperycat | 08/30/05
I know  NonZealot | 08/30/05
How do you know who to trust  wexwimpy@... | 08/30/05
You don't...  Wolfie2K3 | 08/30/05
In summary.  enduser_z | 08/30/05
In Summary: Active X  walterreads@... | 08/30/05
A question for the Microsoft party faithfull  whisperycat | 08/30/05
HAHAHAHA!  NonZealot | 08/30/05
Get the facts, "non-zelaot"  whisperycat | 08/30/05
I have the facts jelly!  NonZealot | 08/30/05
Poor "non-zealot". No facts, resorts to ad hominem.  whisperycat | 08/30/05
Poor jelly  NonZealot | 08/30/05
Zealot's revisionism  whisperycat | 08/30/05
jelly's revisionism  NonZealot | 08/30/05
Wikipedia revisionsm..  Wolfie2K3 | 08/30/05
Did you read your sources?  PMC-CON | 08/30/05
I read my sources, do you understand basic CS?  whisperycat | 08/30/05
Just ensure one thing PMC-CON  NonZealot | 08/30/05
NonZealet, I've Been Recommending WebTV  PMC-CON | 08/30/05
I understand ... Answer Question? FireFox on Windows?  PMC-CON | 08/30/05
get real  doh123 | 08/30/05
doh, you get real  NonZealot | 08/30/05
So you think IE isn't embedded in Windows?  Sir_Chancealot | 08/30/05
Actually...  rapson | 08/30/05
HTML rendering engine...  jacarter3 | 08/30/05
You are right  NonZealot | 08/30/05
You are wrong  jacarter3 | 08/30/05
here's where it falls apart  Dave P. | 08/30/05
Nope, it hangs together  NonZealot | 08/30/05
Overburdened Design ... Historical from Memory Shortages  PMC-CON | 08/30/05
12 Men and the Elephant  PMC-CON | 08/30/05
Oh Snap!  Loverock Davidson | 08/30/05
Since I was asked directly  Loverock Davidson | 08/30/05
Don't worry, Loverock ...  whisperycat | 08/30/05
I'm not worried  Loverock Davidson | 08/30/05
Which websites, exactly?  tic swayback | 08/30/05
Here you go  NonZealot | 08/30/05
That was funny!  Loverock Davidson | 08/30/05
That's too pathetic  jacarter3 | 08/30/05
Re: That's too pathetic  Dave P. | 08/30/05
Re: Re: That's too pathetic *  jacarter3 | 08/30/05
Since you are obviously so smart...  Dave P. | 08/30/05
An answer to the Chicken Little's out there.  Wolfie2K3 | 08/30/05
Save It.  IT Scion | 08/31/05
Once again, MS relies on users  bjbrock | 08/30/05
Relying on users  nitecourt@... | 08/30/05
no_axe_to_grind pro-forma pro-microsoft reply...  BanjoPaterson | 08/30/05
hahahahahaha - genius!  Reverend MacFellow | 08/30/05
10 !  George Jay | 08/30/05
That's too nice to be from Bitty  jacarter3 | 08/30/05
well and succinctly put  the24Frans@... | 08/30/05
So, what's new?  Reverend MacFellow | 08/30/05
RE: So, what's new? ...AMEN!!!  btljooz | 09/01/05
Typical...  BitTwiddler | 08/30/05
How could there possibly be a flaw in IE ???  realitycheck101 | 08/30/05
Microsoft investigates another IE flaw report  Loverock Davidson | 08/30/05
Big Stink  Middle of the Road | 08/30/05
I'm finally convinced  Michael Kelly | 08/30/05
So, no user will ever go to these "bad" websites?  Sir_Chancealot | 08/30/05
Thats not what I said  Loverock Davidson | 08/30/05
Drop down  Anti_Zealot | 08/30/05
anyone with  Dave P. | 08/30/05
8.5  linux_skynyrd | 08/30/05
Another flaw, how can this be, I thought Microsoft fixed them all (NT)  George Jay | 08/30/05
Message has been deleted.  Mike_Coxs_Rep | 08/30/05
Message has been deleted.  widge_z | 08/30/05
Let's Talk GreaseMonkey ...  PMC-CON | 08/30/05
Why? I don't use Greasemonkey.  Zogg | 08/30/05
The Last IE Hole - MSDDS -- was NOT IE  PMC-CON | 08/30/05
"IF it's an add-in hole"??????  Zogg | 09/02/05
Nothing New to Me  bcbooks | 08/30/05
Like I said last week...  Dave P. | 08/30/05
I'll say it again...  ydhptkh1 | 08/30/05
Micosoft flaw #  gamerzworld | 08/30/05
Fix the Flaw please ...  Palmist | 08/30/05
It is nothing at all, at this point.(nt)  IT Scion | 08/31/05
Opportunity to waste my time...  the24Frans@... | 08/30/05
Mystery infection on 08-27-05  dns6 | 08/31/05
You are suffering from "WIndows".  whisperycat | 08/31/05
Wow  IT Scion | 08/31/05
Mystery infection  dns6 | 08/31/05
It sounds to meqlike you DL'd  IT Scion | 09/09/05
Wolfie2K3, you did say to correct you if you were wrong?  whisperycat | 08/31/05
Please!  mujadaddy | 08/31/05
find a flaw , fix a flaw  johni123 | 09/13/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads