iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > News > Security News > IE Exploits Hit The Web
Search:
[ news_security_news ]

IE Exploits Hit The Web



David Utter
Staff Writer
2006-03-27

SecurityProNews: Insider Reports Insider Reports RSS Feed


The createTextRange() method exploit could permit the arbitrary execution of code through Internet Explorer, and malicious sites that take advantage of the as-yet-unpatched flaw have been sighted online.

By disabling Active Scripting in IE as recommended by Microsoft, users should be able to avoid the impact of a highly critical flaw in the browser. Both Secunia and Sophos have reported exploit code being in the wild.

Should a Windows user running IE with Active Scripting enabled and administrative rights on the PC encounter this malicious code online, the system could be exploited and remote code executed by an unknown user.

Microsoft has confirmed the existence of the flaw and has a patch in development. It is not known whether Microsoft will release the patch early, or wait until its next scheduled patch release date of April 11th.

Sooner may be better than later, as a representative with Sophos noted on their website today:

Microsoft is warning users to exercise caution when opening email messages, and web links in email messages, from untrusted sources.

"With no patches yet available to plug this hole, both home users and businesses need to exercise caution here," said Carole Theriault, senior security consultant at Sophos. "Users without any additional security measures, such as firewall and anti-virus software, and users who surf the web and open emails and without care, are at much higher risk that those who practice safe computing."


---
Taga: ,

Add to | DiggThis | Yahoo! My Web

Get all the updates in RSS:





About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More news_security_news Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds