Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Virus and Vulnerability Roundup
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Researchers reveal new Explorer, Outlook security flaw

 

Sign up to receive Security Resource Alerts

July 11, 2002 (IDG News Service) -- Researchers have identified a fresh security flaw in Microsoft Corp.'s Internet Explorer Web browser and Outlook e-mail client that can leave systems open to malicious code inserted in e-mails or Web pages, network security consultancy PivX Solutions LLC said yesterday.
The hole is created by what is known as a cross-domain scripting flaw. In this case, it means that HTML Version 4 objects embedded in Web pages and e-mails can include code that allows an attacker to access vulnerable machines, read files and documents, and execute programs on the computer, PivX said in an advisory.
PivX described the vulnerability as "extremely high risk," as it allows the arbitrary execution of programs, unprivileged reading of files and stealing of server cookies.
The flaw occurs because of the Object element used to embed external objects inside an HTML 4 page. Such objects can be the WebBrowser control and other ActiveX controls, images, applets and more. The Object property of embedded WebBrowser controls isn't subject to the cross-domain security checks that embedded HTML documents ordinarily go through, and as such it is possible to escape any sandboxing and security zone restrictions, PivX said.
In testing, PivX has demonstrated the flaw in Internet Explorer 5.5 running on both Windows 98 and Windows NT and on Internet Explorer 6 running on Windows 2000. The flaw also affects the Outlook and Outlook Express e-mail clients.
A quick work-around for end users involves disabling ActiveX, or setting "Script ActiveX controls marked safe for scripting" to Prompt or Disable, according to the PivX advisory.
The flaw was discovered on June 25, and Microsoft was informed the same day, PivX said.
PivX decided to release its findings in the light of a survey last month by consulting firm Hurwitz Group Inc. in Framingham, Mass., regarding the disclosure of security flaws.
"End users surveyed for the report are clearly angry that vendors are releasing insecure applications and then not responding when flaws are detected," Hurwitz wrote in the report. "While it seems that putting their own companies at risk (by publicizing a flaw before a patch is available) seems counterintuitive, end users are so frustrated with unresponsive vendors that they are willing to try almost anything."





Reprinted with permission from

For more news from IDG visit IDG.net
Story copyright 2006 International Data Group. All rights reserved.


Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"A couple of weeks ago at..." Read more...
"Most security companies tend to take a horizontal approach looking to capitalize on the finance, service provider, and federal government..." Read more...
Read more Security posts or See all Blogs
Elgan: You can be Batman, too
Study: IT jobs will drop in 2009
RIM fixes critical BlackBerry Enterprise Server bug
More top stories...
Apple's recall demand would probably kill Psystar, says IP attorney
DNS flaw discoverer says more permanent fixes will be needed
AT&T muffs free iPhone Wi-Fi offer again
With the opening of Apple's App Store, the iPhone takes a revolutionary leap from cool mobile phone to hot mobile platform. See our list of apps you should definitely check out for yourself.
Its motto is "Don't be evil" — but it looks like anything and everything else imaginable is pretty much fair game — not to mention some wildly rumored projects that we asked the company to confirm or deny.
The talk at three big research houses is all about "open innovation." Is that a feel-good catchphrase or the R&D strategy of the future?
After months of waiting for a 3G-based iPhone — and hours waiting in line to actually buy one — Ryan Faas says it "packs quite a punch, both in its design and in the 3G and GPS capabilities" it offers.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
Data Center Management Zone
Enterprise-Class Security Zone
The File Data Management Zone
Grid Computing on Windows Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Storage Virtualization Zone
Business Intelligence and Analytics Zone

Ads by TechWords

See your link here
Why SaaS is Vital to Email and Web Security
Why SaaS is Vital to Email and Web Security
Download this webcast, free, compilments of Webroot Software
Go to the webcast 
Managing Mobile Data with Endpoint Security for Laptops
Download this white paper now, compliments of Computerworld and Absolute Software.
(Source: Absolute Software) A NetworkWorld survey of IT professionals found that only 1 in 100 employees consistently follow data security policy. This paper outlines endpoint security for laptops that restricts data access beyond encryption to safeguard against insider threats and user error. Read this whitepaper to learn lessons from recent data breaches, limitations of traditional data security, and how to remotely wipe out data and monitor computers that go off the network.
Download this executive briefing download
Top 10 Reasons to Upgrade
Get this white paper now!
(Source: Symantec) Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
New Fujitsu High-End Itanium Windows- and Linux-Based PRIMEQUEST Servers Offer the Utmost in High Availability
New Fujitsu High-End Itanium-Based PRIMEQUEST Servers Offer Industry-Leading System Management for Linux and Windows
Web Security SaaS: The Next Generation of Web Security
View more whitepapers