nellie2 Posted March 26, 2006 Report Share Posted March 26, 2006 Secunia Research has discovered a vulnerability in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error in the processing of the "createTextRange()" method call applied on a radio button control. This can be exploited by e.g. a malicious web site to corrupt memory in a way, which allows the program flow to be redirected to the heap. Successful exploitation allows execution of arbitrary code. NOTE: Exploit code is publicly available. The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2. The vulnerability has also been confirmed in Internet Explorer 7 Beta 2 Preview (January edition). Other versions may also be affected. Solution: Disable Active Scripting support.sourceThis is serious, you are vulnerable to this exploit even if you use a different browser like Firefox, IE can still be launched to allow this attack to take place.Advice; Be careful about the sites you visit, stick to your tried and tested ones for nowDisable active scripting, doing this may effect the way some websites behave. So add your favourite and regular sites to your trusted zone, that way they will work properly. See here for tutorial Quote Link to comment Share on other sites More sharing options...
-pops- Posted March 26, 2006 Report Share Posted March 26, 2006 There is a date of 22-11-2005 on your link, nel. Does this mean this exploit has been around since then and no-one (i.e Secunia) has taken any notice until now?Have there been any instances of this exploit occurring?It always worries me that the mere publication of information like this by concerns such as Secunia will encourage the less scrupulous amongst us to work even harder to produce whatever is required to cuff up people's machines. Why, when they discover these nasties, don't they have a quiet word with Mr Gates and his crew and work towards a remedy behind the scenes?I carried out the changes in the link to ZDNet. Not a single web page that I tried to open did so correctly. I've changed the settings back. Seems like you need to add your trusted pages before trying to open but, if you do that, how do you access new pages for a one-off viewing? I'm not going to go through the procedure of adding every web page I ever want to look at into a special little box just so I can look as it for a couple of seconds. Or have it got it wrong? Quote Link to comment Share on other sites More sharing options...
nellie2 Posted March 26, 2006 Author Report Share Posted March 26, 2006 I've been following a discussion on this and it seems that only a certain few sites are affected (that they know of!!) and I'm sure they wouldn't be the type of sites that you would visit -pops-There are some more useful links and information on this thread at Calendar of Updates Quote Link to comment Share on other sites More sharing options...
-pops- Posted March 26, 2006 Report Share Posted March 26, 2006 Hmmm... as I thought would happen: Folks, as Lorna predicted yesterday, it didn't take long for the exploits to appear for that IE vulnerability.From the Calendar of Updates given by nel. I suspect these are entirely a result of the publicity. Quote Link to comment Share on other sites More sharing options...
scuzzman Posted March 28, 2006 Report Share Posted March 28, 2006 Here's a more up-to-date article on the subject at hand. That said, Microsoft apparently has no intention of patching it until April 11. For the mean time though, eEye has released a patch that will uninstall itself when MS's is applied. More information is available at eEye. Quote Link to comment Share on other sites More sharing options...
andsome Posted March 28, 2006 Report Share Posted March 28, 2006 Got the download thanks. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.