New Flaws Reported In Microsoft IE 6 Browser

Newly discovered security flaws in Microsoft’s Internet Explorer could let attackers invade a user’s PC, but a fix is not yet available. Danish security firm Secunia warned that when used together, the flaws could allow an attacker to execute malicious code on a user’s PC.

The flaws were reported this week by researcher Liu Die Yu, who posted the information on public security messaging boards, and appear to exist on PCs that are patched with the latest Microsoft security updates. Users are advised to switch off active scripting in Internet Explorer until a patch becomes available, or to use a non-IE browser.

Instructions on disabling active scripting, which may keep some sites from functioning properly, are available from the Computer Emergency Response Team. One of the flaws is a cross-site scripting vulnerability, allowing scripts from one security domain (such as the Internet) to execute with the security privileges of another domain (such as My Computer).

Secunia said it had verified the flaw on IE 6, but the problems may affect earlier versions of the browser. “Other versions may also be affected, and have been added (to the advisory) due to the criticality of these issues,” the company said in a statement.

Share and Enjoy:
  • Digg
  • Technorati
  • StumbleUpon
  • del.icio.us
  • Reddit
  • Google Bookmarks
  • TwitThis
  • Facebook

Warp2Search

Related posts:

  1. Microsoft Releases Update for Browser
  2. New IE, Mozilla Flaws Exposed
  3. Microsoft warns of a score of security flaws
  4. New Microsoft security flaws found
  5. Exploit code makes IE flaw more dangerous

Comments are closed.


GamersCircle is Digg proof thanks to caching by WP Super Cache