NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


PoC Published for Internet Explorer 7 Vulnerability

The flaw still has to be confirmed

By Marius Oiaga, Technology News Editor

14th of December 2006, 16:10 GMT

Adjust text size:


Proof of Concept code has been released in the wild for download today, 14 December 2006. The PoC is related to an alleged vulnerability affecting Internet Explorer 7. According to the
vulnerability reports, IE7 is vulnerable to DLL-load hijackings. According to Aviv Raff, the person that discovered the IE7, Microsoft was informed about the issue.

At the time of this article, an official comment from Microsoft was not available. Additionally, the vulnerability could not be confirmed as authentic. "It has been over a month since my last post regarding the IE7 vulnerability. The feedbacks to this issue were mixed. Some said it's an issue that should be fixed as soon as possible, other said it's a minor issue, a hoax or just "old news". Well, although I did not give the full information in my last post, it is definitely not a hoax, and as far as I know (and Google knows) no one ever informed about this specific issue in Internet Explorer," stated Raff.

Defending the authenticity of the IE7 vulnerability, Raff stated that "sqmapi.dll," "imageres.dll" and "schannel.dll" are DLL file names that can be used in a successful exploit of the IE7 DLL-load hijacking vulnerability. A Proof-of-Concept code for this vulnerability can be accessed via this link.

If you want additional details about the DLL-load hijacking IE7 vulnerability, they are available here.
Read by 2,626 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Very Good (4.5/5) 8 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Internet Explorer 7 Immune to October's Vulnerabilities

Free IE6 VPC + Windows XP SP2 = a Microsoft Success

IE7 Redirected 1.2 Million Phishing Attacks in 2 Weeks

Internet Explorer 7 Down - Firefox 2.0 Up

Windows Live OneCare Updated with Anti-phishing Technology Activation

Security Vulnerabilities in Internet Explorer 7

3.06 Percent Global Share for Internet Explorer 7

Upgrade to IE7 Optimized for Google

The Internet Explorer 6 Virtual PC - Run IE6 and IE7 Side by Side

IE7 Speaks Chinese and Hebrew

Vista-ready Flash Player 9 Integrates with IE7 Protect Mode

Microsoft Removes IE7 Update from WSUS

The First Internet Explorer 7 Vulnerability

Internet Explorer 7 - Zero Vulnerabilities

The First Update for Internet Explorer 7

Fishing Details Out of the Firefox 2.0 and IE7 Anti-Phishing Reports

Seven December 2006 Security Bulletins

PoC Available for Patched Microsoft Vulnerability

Build Your Own Customized IE7

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM