NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Patches and Vulnerabilities

Patches and Vulnerabilities


Windows 7’ IE8 Dodges Critical IE 0-Day

Workarounds available

By Marius Oiaga, Technology News Editor

24th of November 2009, 08:44 GMT

Adjust text size:


Internet Explorer
Enlarge picture
Customers already running the latest iteration of the Windows client, Windows 7, along with the Internet Explorer 8 are safe from potential exploits targeting a zero-day vulnerability in older releases of Internet Explorer, according to Microsoft. In an email message to Softpedia, Alan Wallace, security response communications, Microsoft, explains that only pre-IE8 versions of Microsoft’s proprietary browser are affected, but with the exception of Internet Explorer 5.01 Service Pack 4. The Redmond company has also published a security advisory detailing the latest IE vulnerability for which details have been already published in the wild.

“The vulnerability exists as an invalid pointer reference of Internet Explorer. It is possible under certain conditions for a CSS/Style object to be accessed after the object is deleted. In a specially-crafted attack, Internet Explorer attempting to access a freed object can lead to running attacker-supplied code,” Microsoft explained.

Most importantly, the security advisory in question describes the measures that customers can take in order to protect themselves against attacks. Of course, a simple thing that users can do to ensure that no attacker will be able to exploit the new zero-day vulnerability on their machine is to upgrade to the latest version of Internet Explorer, namely IE8.

However, for those customers that for any given reason cannot upgrade to IE8, Microsoft details a range of alternative workarounds under the Suggested Actions area of the security advisory. Customers can choose to “Set Internet and Local intranet security zone settings to "High" to prompt before running ActiveX Controls and Active Scripting in these zones;” “Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone,” [and] “Enable DEP for Internet Explorer 6 Service Pack 2 or Internet Explorer 7,” Microsoft noted.

“The vulnerability impacts Internet Explorer 6 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6 and Internet Explorer 7 on supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008,” Wallace stated. “Microsoft Internet Explorer 5.01 Service Pack 4 and Internet Explorer 8 on all supported versions of Microsoft Windows are not affected. This includes the recently released Windows 7. Microsoft is recommending that customers with earlier versions of the browser consider downloading the more recent version of IE to take advantage of the latest security and privacy features.”

Microsoft stressed the fact that, as the start of this week, it had not detected attacks designed to exploit the vulnerability against IE6 SP1 and IE7. However, Proof of Concept code has already been irresponsibly published in the wild putting all those still running IE6 and IE7 at risk.

“The company is aware of public, detailed exploit code that allows an attacker to gain the same rights as a local user; however, the exploit code requires an attacker to convince users to visit a maliciously-crafted Web site,” Wallace added. “The company is not aware of attacks to exploit the reported vulnerability at this time. While Microsoft is not currently aware of active attacks, the company recommends customers review and implement the workarounds outlined in the advisory until a comprehensive security update is released.”

Internet Explorer 8 (IE8) is available for download here.

TAGS:

IE7 | IE6 | IE8 | vulnerability | 0-day
Read by 2,065 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 1 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Internet Explorer 9 (IE9) - Behind the Curtain

Internet Explorer 9, the Evolution

Free IE8 Mouse Gestures Add-on Available for Download

Internet Explorer 9 (IE9) First Taste Coming Right Up

Download Office 2010 Beta Soon, Official Website Up and Running

Download SQL Server 2008 R2 November CTP

Zero-Day Windows 7 RTM DoS Vulnerability Has PoC Published in the Wild

Microsoft and CHT Form Cloud Alliance

User opinions:


Comment #1 by: bob on 25 Nov 2009, 07:47 GMT reply to this comment

The folks running IE6 and IE7 should just upgrade to IE8 already. If they're adamant about staying with the same browser, either MS should make an IE6 'skin' for IE8, or someone should make an IE6 skin for Firefox, to ease the transition to a modern browser.


Comment #2 by: devilmaster on 25 Nov 2009, 09:32 GMT reply to this comment

The problem is not look and feel (at least not for most). The problem is that the HTML and JavaScript implemented in IE6 are sufficiently different from all other browsers that certain line of business apps built to work in IE6 will not work properly in anything else ... that is the real problem. I haven't seen home users with IE6 for a while ... most of them are in companies who either have the type of apps i described above or have some stupid standardization policy that forbids anything except IE6 (sounds absurd i know that 3 years after IE7 has launched there are still such companies ... but there are ..)

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM