NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Internet Explorer 7 - Scarred By Vulnerabilities

With a severity rating of Important

By Marius Oiaga, Technology News Editor

14th of February 2007, 10:34 GMT

Adjust text size:


Internet Explorer 7 immaculate record is on its way down the drain. Concomitantly with the release of the February 2007 Security Bulletins, Microsoft has also made available patches
for vulnerabilities scarring the latest version of its browser.

Two privately reported vulnerabilities related to COM Object Instantiation Memory Corruption affect a range of Microsoft browsers including Internet Explorer 5.01, 6, and 7. Only the issues impacting Versions 5 and 6 of Internet Explorer are considered Critical.

"A remote code execution vulnerability exists in the way Internet Explorer instantiates COM objects that are not intended to be instantiated in Internet Explorer. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could potentially allow remote code execution if a user viewed the Web page. An attacker who successfully exploited this vulnerability could take complete control of an affected system," informed Microsoft.

However, Microsoft has informed that only IE7 for Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1 are affected. The IE7 that ships with Windows Vista is in no way impacted by the vulnerabilities. Microsoft has released a cumulative security update for Internet Explorer.

"Included in this release are 'Important' security updates for Internet Explorer 7 for Windows XP SP2 and Windows Server 2003 SP1 that disable specific COM objects not intended to be instantiated in Internet Explorer. While these vulnerabilities are considered 'Critical' in IE5 and IE6, the objects are blocked by the ActiveX Opt-in feature in IE7, preventing attacks that use non-approved controls from running an exploit. Since some users may turn off ActiveX Opt-in or mistakenly permit the objects to load without prompt, this update disables loading these objects to provide further defense-in-depth. IE7 in Windows Vista already disables these objects and is not affected by this update," revealed Geoffrey Silva, IE Program Manager.
Read by 1,555 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.6/5) 9 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Internet Explorer 8.0 Available for Download on Peer-to-Peer Networks

The First Security Vulnerability in Internet Explorer 7

Microsoft Revamped IE Add-ons

Microsoft Updates the IE7 Phishing Filter

Manage Internet Explorer 7 Protect Mode

IE7 Security Features Should, In Theory, Protect the Computer?

IE 7 Global Usage Share Grows to 10.97%

Microsoft Contracts Web Standards Evangelist

IE7 - the First Browser to Support EV SSL Certificates

Internet Explorer 7 Feeds Plus

Internet Explorer 8 Feature Survey Email

Internet Explorer 7 Blocks 1 Million Phishing Attacks Per Week

Targeted Attack Scenario via a Microsoft Vulnerability

Microsoft in the House of Lords

Microsoft Confirms Word 2000 Zero-Day

Download Thunderbird 2.0 Beta 2

Microsoft Phonetically Corrects Excel Patch

It's Raining Word Vulnerabilities

Gran Paradiso Alpha 2 Is Way Ahead of Internet Explorer 8.0

Microsoft Responds to Symantec Claims of the Fifth Word Zero-Day

Highly Critical Microsoft Word Zero-Day

Has Microsoft Updated Windows Media Player 11?

Microsoft Vulnerabilities in the Front Row at Super Bowl

A Bouquet of a Dozen Microsoft Security Bulletins, Please!

List Feed Management - Internet Explorer 7

Microsoft's 12 Valentine Security Patches

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM