On The Insider: Jon Hamm to Join 30 Rock
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Nov 30, 2005 8:16:00 PM

Attackers are taking advantage of an unpatched vulnerability in Internet Explorer to target users of the ubiquitous Web browser, Microsoft warned late Tuesday.

Malicious software that exploits the security flaw to download a Trojan horse to vulnerable computers has been found on the Internet, according to Microsoft. Detection and removal capabilities for the "TrojanDownloader:Win32/Delf.DH" have been added to Microsoft's recently launched online security-scanning tool.

"Customers can visit Windows Live Safety Center and are encouraged to use the Complete Scan option to check for and remove this malicious software and future variants," Microsoft said in its updated security advisory on the issue.

The security bug, exploited by the Trojan downloader, was originally reported in May. The bug was thought to only allow for a denial-of-service attack, which would cause IE to close. However, experts last week raised an alarm on the issue because it was discovered that it could be used to remotely run code on a vulnerable computer.

Microsoft has yet to provide a fix for the vulnerability, but is working on a patch, according to the security advisory. Security-monitoring company Secunia deems the problem "extremely critical," its rarely given highest rating.

The vulnerability puts computers running Windows 98, Windows Millennium Edition, Windows 2000 and Windows XP at risk. An attacker could gain complete control of vulnerable systems by hosting malicious code on a Web site. Once an IE user visits the site, the malicious program would run without any user interaction.

Microsoft offers several workarounds to deflect attacks. These include changing IE settings to disable active scripting or prompt the user before running such scripts.

  • Talkback
  • Most Recent of 59 Talkback(s)
Alerts
I appreciate your alerts. However, it would be really helpful if you also included solutions. (Read the rest)
Posted by: Widget_z Posted on: 12/29/05 You are currently: Logged In as: a Guest  | Login | Terms of Use
Whew, Missed That One  RobertoSalazar | 11/30/05
maybe you got it anyway  Boot_Agnostic | 11/30/05
Windows users could lose control of their systems by simply visiting a Web"  BitTwiddler | 11/30/05
Don't surf with Windows  Chad_z | 11/30/05
Yeah. Simplistic Pollyanna response. (IMHO)  jrbeaman | 12/01/05
Rep has contacted me...  Mike Cox | 11/30/05
10.0 Mikey!!  DragonBRockin | 11/30/05
You gotta admit  I'm Ye, the MS SHILL . | 11/30/05
Easy now...  IT Guy fmr w/ Fortune 50 | 12/01/05
bad assumption  Real World | 12/01/05
You are the fish, and you've been caught.  jrbeaman | 12/01/05
Apparently, the concept was lost on you  Real World | 12/01/05
Patch This  christopherarchitect | 12/01/05
Wake up and learn how to spell S A T I R E !!!  jrbeaman | 12/01/05
What do your MCSEs know?  IT-sys | 11/30/05
Fish On!  zmud | 12/01/05
9.5  sokushi jonez | 12/01/05
Use Firefox  nikoli | 11/30/05
UH, ok. Yeah Sure. (IE still runs inside)  jrbeaman | 12/01/05
You MUST Be An Architect Since You Know IE Is In All Windows Software  PMC-CON | 12/01/05
You MUST Be An Architect Since You Know IE Is In All Windows Software  PMC-CON | 12/01/05
You MUST Be An Architect Since You Know IE Is In All Windows Software  PMC-CON | 12/01/05
You MUST Be An Architect Since You Know IE Is In All Windows Software  PMC-CON | 12/01/05
Everyone else is pretty much releasing new s/w  michael_t | 11/30/05
MS recommends using *beta* Windows Live Safety Center?!  PB_z | 11/30/05
Not really ....  michael_t | 11/30/05
Monopolies, homogeny, and fascists have one thing in common:  HypnoToad | 11/30/05
Yet another revenue plan from Microsoft.  Cardinal_Bill | 11/30/05
Ohhh my.... so quiet here in this forum. None of the  michael_t | 11/30/05
So Share Your Software Project, Dr. T  PMC-CON | 12/01/05
Calling non-zealot, shadetree, Loverock et al  whisperycat | 12/01/05
You missed this  Middle of the Road | 12/01/05
"The internet used to be a nice place" -JB  jrbeaman | 12/01/05
Calling all trolls! Calling all trolls!  whisperycat | 12/01/05
reply to: Calling all trolls! Calling all trolls!  windy@... | 12/01/05
List Stolen From George Ou's Blog  PMC-CON | 12/01/05
List Stolen From George Ou's Blog  PMC-CON | 12/01/05
Only One in List Above Not Critical  PMC-CON | 12/01/05
Message has been deleted.  whisperycat | 12/01/05
I'd like to delete these hackers!  zindorf1 | 12/01/05
Calling on call waiting  Boot_Agnostic | 12/01/05
Look behind you  Boot_Agnostic | 12/01/05
Trojan Horse rides on unpatched IE flaw...and more  windy@... | 12/01/05
Cost of Switching or Upgrading is  Betelgeuse58 | 12/01/05
"STOP the GREED and get COMPETITIVE"  jrbeaman | 12/01/05
jr  Betelgeuse58 | 12/01/05
Competetive pricing  lobo1953 | 12/01/05
pc defenses  bukti | 12/03/05
pc defenses  bukti | 12/03/05
Why do I have to keep paying for MS's flaws?  juvii | 12/01/05
You're Paying Microsoft -- Long Pay Plan for W98  PMC-CON | 12/01/05
Sorry you did't get the analogy  juvii | 12/01/05
RE: Why do I have to keep paying for MS's flaws? by R. W. Minor  btljooz | 12/01/05
RE: Why do I have to keep paying for MS's flaws? by R. W. Minor  btljooz | 12/01/05
Caveat emptor  Allstar_z | 12/03/05
MacOSX + Firefox = 'No problem'  999ad@... | 12/01/05
Linux + many applications and tools = best solution  Boot_Agnostic | 12/02/05
Microsoft strikes again!  jonkopp | 12/05/05
Alerts  Widget_z | 12/29/05

What do you think?

Fusion

advertisement
Click Here