NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Microsoft Investigating Vulnerabilities in IE7 and Windows Vista

Currently, Microsoft has two Windows Vista vulnerabilities under investigation

By Marius Oiaga, Technology News Editor

27th of February 2007, 10:23 GMT

Adjust text size:


Two vulnerabilities impacting Internet Explorer 7 and Windows Vista are being scrutinized by Microsoft. The Redmond Company is currently investigating two low risk flaws identified in
Internet Explorer 7 and Windows Vista. Microsoft is not considering any of the two bugs as presenting a high-risk to customers.

The vulnerability affecting Internet Explorer 7 is related to an error in the "onunload" events management in the browser. The flaw "could be exploited by attackers to spoof the displayed address bar by tricking a user into entering a trusted URL manually in the address bar while visiting a malicious web page," informed the French Security Incident Response Team.

Via the onunload IE7 vulnerability, an attacker can trap users in a malformed web page while tricking them into thinking that they have navigated to a genuine address. There is a great chance that the onunload flaw will be used in spoofing phishing attacks.

Microsoft is also evaluating a new flaw in Windows Vista. The Microsoft Windows ReadDirectoryChangesW() vulnerability was attributed a low severity rating. "A weakness has been identified in Microsoft Windows, which could be exploited by malicious users to disclose sensitive information. This issue is due to an error within the "ReadDirectoryChangesW()" API that does not properly validate user's permission for child objects when retrieving information regarding objects that they do not have "LIST" permissions for, which could be exploited by local attackers to gather information about protected files (e.g. their names), facilitating further attacks," revealed the French Security Incident Response Team.

Currently, Microsoft has two Windows Vista vulnerabilities under investigation. Both present a low risk to users.
Read by 757 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.6/5) 8 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Internet Explorer 7 - Scarred By Vulnerabilities

IE and Firefox Fight for the "Most Vulnerable Browser" Award

IE7 Security Features Should, In Theory, Protect the Computer?

Internet Explorer 8 Unveiled in 62 Days?

Firefox 2.0 Flaws Outperform the Vulnerabilities in IE7

The First Security Vulnerability in Internet Explorer 7

Vista Down-Level Features Available on XP

Microsoft Updates the IE7 Phishing Filter

Vista vs. XP - Feature Comparison

Internet Explorer 8.0 Available for Download on Peer-to-Peer Networks

Microsoft Revamped IE Add-ons

It's Raining Word Vulnerabilities

Targeted Attack Scenario via a Microsoft Vulnerability

IE7 and Firefox 2.0 Share Vulnerabilities

Microsoft Contracts Web Standards Evangelist

IE7 - the First Browser to Support EV SSL Certificates

Microsoft Responds to Symantec Claims of the Fifth Word Zero-Day

The Internet Explorer 7 "Matrix" Has You

Microsoft Vulnerabilities in the Front Row at Super Bowl

Gran Paradiso Alpha 2 Is Way Ahead of Internet Explorer 8.0

Internet Explorer vs. Firefox Battle Continues

Internet Explorer 7 Blocks 1 Million Phishing Attacks Per Week

Get a Free Copy of Windows Vista Ultimate at MIX07

McAfee Delivers Full Windows Vista Compatibility

Windows Vista Has Issues Handling Photo Metadata

Hack Windows Vista in Reduced Functionality Mode

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM