iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > News > Security News > Microsoft Prepping IE Pre-Patch Tuesday Fix
Search:
[ news_security_news ]

Microsoft Prepping IE Pre-Patch Tuesday Fix



David Utter
Staff Writer
2006-03-23

SecurityProNews: Insider Reports Insider Reports RSS Feed


A highly-critical vulnerability in Internet Explorer has prompted Microsoft to scramble for a workaround to the flaw.

Only rarely does Microsoft release security fixes outside its normal second Tuesday of the month patch release cycle. But the problem that exists with Internet Explorer has proven so troubling that it will make some type of workaround available as soon as possible, eWeek reported.

Researcher Andreas Sandblad with the Secunia monitoring website noted users of IE should disable Active Scripting until the patch is released. He posted more details about the problem as part of Secunia's advisory:

The vulnerability is caused due to an error in the processing of the "createTextRange()" method call applied on a radio button control. This can be exploited by e.g. a malicious web site to corrupt memory in a way, which allows the program flow to be redirected to the heap.

Successful exploitation allows execution of arbitrary code.

The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2. The vulnerability has also been confirmed in Internet Explorer 7 Beta 2 Preview (January edition). Other versions may also be affected.

Microsoft Lennart Wistrand confirmed the problem and also recommended turning off Active Scripting in an entry at the Microsoft Security Response Center Blog:

Our initial investigation has revealed that if you turn off Active Scripting, that will prevent the attack as this requires script. Customers who use supported versions of Outlook or Outlook Express aren't at risk from the email vector since script doesn't render in mail (being read in the restricted sites zone).

We're going to continue to look into this but remind you also that safe browsing practices can help here, like only visiting trusted websites, etc.

Users can watch Microsoft's advisory page for the update.

---
Tags: , , |

Add to | DiggThis | Yahoo! My Web

Get all the updates in RSS:





About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More news_security_news Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds