On TechRepublic: The 5 worst tech products of 2009
BNET Business Network:
BNET
TechRepublic
ZDNet

By Matthew Broersma
Posted on ZDNet News: Nov 29, 2003 1:55:00 AM

Newly discovered security flaws in Microsoft's Internet Explorer could let attackers invade a user's PC, but a fix is not yet available.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


Danish security firm Secunia warned that when used together, the flaws could allow an attacker to execute malicious code on a user's PC.

The flaws were reported this week by researcher Liu Die Yu, who posted the information on public security messaging boards, and appear to exist on PCs that are patched with the latest Microsoft security updates. Users are advised to switch off active scripting in Internet Explorer until a patch becomes available, or to use a non-IE browser.

Instructions on disabling active scripting, which may keep some sites from functioning properly, are available from the Computer Emergency Response Team.

One of the flaws is a cross-site scripting vulnerability, allowing scripts from one security domain (such as the Internet) to execute with the security privileges of another domain (such as My Computer).


Special report
A 20-year plague
Decades after creation,
viruses defy cure


Secunia said it had verified the flaw on IE 6, but the problems may affect earlier versions of the browser. "Other versions may also be affected, and have been added (to the advisory) due to the criticality of these issues," the company said in a statement.

Microsoft has said it is investigating the issue, and may issue a fix as part of its monthly patch release, or separately, depending on the severity of the problem. Microsoft's last cumulative monthly patch was issued on Nov. 12.

Matthew Broersma of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 72 Talkback(s)
November 28, 2003!? That's news?
a (Read the rest)
Posted by: caktus Posted on: 01/23/04 You are currently: a Guest | | Terms of Use
THIS JUST IN...  Yen_z | 11/28/03
Darwin would be proud.  TheTruthisOutThere@... | 11/29/03
On our desktops, as in Nature...  Yen_z | 11/29/03
Nothing lasts forever  TheTruthisOutThere@... | 11/29/03
And then....  master of illusion | 11/29/03
In retrospect  LinuxHippie | 12/01/03
And in the end...  Yen_z | 12/01/03
Out Of The Inner Circle  Harry.Shipley@... | 12/02/03
THIS JUST IN...  NemesisNL | 11/30/03
Re: THIS JUST IN...  Martin Marvinski | 11/30/03
My apologies.  Yen_z | 12/01/03
bushpig? you dont know them well do you  crocd | 12/01/03
This is not news  DarthRidiculous | 11/28/03
Consumers are dumb............  middle of nowhere | 11/29/03
HEY!  Yen_z | 11/29/03
Re: HEY!  Martin Marvinski | 11/30/03
please offer alternatives  texasfred | 11/29/03
Re: please offer alternatives  Martin Marvinski | 11/30/03
OSX!!!!  cweider | 12/01/03
Alternatives are limited  voska | 12/01/03
If you want to play games  MarcB_z | 12/01/03
Digicams and Windows...  ryusen | 12/01/03
games of mac  broadway al | 12/11/03
It's called Apple Macintosh! Blows Windows away in every way!  MacGeek2121 | 12/01/03
It will cost a little more, but.....  Rick_K | 12/01/03
Say it isn't so Batman!  GRindinAxTaRupy | 11/29/03
Holy Security Flaws, Batman  master of illusion | 11/29/03
Such a none issue  Mike Cox | 11/29/03
The whole world is happy with you.  nucrash | 12/01/03
Good One Mike :_)  michael-t | 12/01/03
I don't understand.  Yen_z | 12/01/03
I don't understand it either...  emartin_z | 12/01/03
And you get the...  Yen_z | 12/01/03
The problem is not that serious than claimed  pa2004 | 11/30/03
The problem is not that serious as claimed  pa2004 | 11/30/03
Frankly, its not a big concern for me  FilledOut | 11/30/03
re: Frankly, its not a big concern for me  Martin Marvinski | 11/30/03
I Find that with....  The Real Bitch | 12/01/03
Proactive system protection good for all OSes  FilledOut | 12/01/03
When was the last time they went 1 week without bad news??  DonnieBoy | 11/30/03
Linux Success Stories  chrichton99 | 12/01/03
That SCO thing...  MarcB_z | 12/01/03
Lack of applications?  jasonp@... | 12/01/03
Lack of applications?  noShut_z | 12/01/03
Um...  Patrick Jones | 12/01/03
Same Um...  noShut_z | 12/01/03
Replacements  jasonp@... | 12/01/03
nutcases  ryusen | 12/01/03
Pot, Kettle, Black?  Rick_K | 12/01/03
I may be different than most, but ...  MacGeek2121 | 12/01/03
The Reality of Linux  voska | 12/01/03
spoutNot...  noShut_z | 12/01/03
Just of few points  voska | 12/01/03
YET...  bhanes@... | 12/01/03
Not that low...  noShut_z | 12/01/03
If productivity includes many hours of troubleshooting and...  MacGeek2121 | 12/01/03
Oh, 1 million desktops in China is not significant? And SCO may be good.  DonnieBoy | 12/01/03
Desktop Inroads...  Martin Marvinski | 12/01/03
t's about what they have done  ryusen | 12/01/03
VERY old information in solution link  junkmail23227@... | 12/01/03
I Find That With...  The Real Bitch | 12/01/03
Requested Linux replacements...  jasonp@... | 12/01/03
Replacements???  noShut_z | 12/01/03
Opinions???  jasonp@... | 12/01/03
You mean it's not flat!!!  noShut_z | 12/01/03
IE Flaws? Not really to me.  michael-t | 12/01/03
New flaws? That's because you installed the new patches.  toomuchgreeatea@... | 12/01/03
Standard Microsoft Security Alert Template  Knorthern Knight | 12/01/03
Funny but sad  Rick_K | 12/01/03
And ppl continue to purchase the system  FilledOut | 12/01/03
Not Another?  TEBushmaker | 12/01/03
November 28, 2003!? That's news?  caktus | 01/23/04

What do you think?

advertisement
Click Here
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here