MS issues security warnings for Internet Explorer
Posted on 6 Feb 2003 at 12:23
Microsoft has issued a security warning regarding Internet Explorer.
Security Bulletin Security Bulletin MS03-004 is actually a cumulative patch containing previously released fixes for IE 5.01, 5.5, 6.0. It also, however, tackles two new vulnerabilities relating to domain information.
It seems IE has a flaw that allows one Web site to potentially access information from another domain when using certain dialog boxes. It means an attacker could craft a Web site to run malicious script through the use of such a dialog box. In the worst case, the attacker could load malicious code on to a system and also invoke an executable present on the local system
The important point is that it affects all machines with IE installed. Users of alternative browsers are still affected if they have IE on their systems. Microsoft has given the problem a severity rating of 'critical'.
To find which service packs are required for which versions you can consult Security Bulletin MS03-004.
A related cross-domain vulnerability allows involves Internet Explorer's use of the HTML-related showHelp function. Without executing proper security checking, this functionality lets an attacker access user information and invoke or load executables.
Microsoft has also issued another security update for Windows XP. This relates to user privilege settings and the means by which an attacker can override restricted access to an XP system. You can read more info about this problem in Security Bulletin MS03-005.
From around the web
advertisement
- Laptop bag reviews: nine tested
- Sony VAIO T Series Ultrabook review: first look
- Revealed: the military standards and robots HP uses to test its laptops
- Windows 8: multi-monitors and double standards?
- Why is TalkTalk's year-old porn filter suddenly big news?
- Why are laptop screens so far behind mobiles?
- HP EliteBook Folio review: first look
- The shoebox-sized all-in-one printer
- Forget the Ultrabook: here comes the HP Sleekbook
- HP Spectre XT review: first look
- Why you have to be left in the dark on OS patches
- Publishing your email address isn't a security disaster
- Why antivirus is fighting a losing battle in your office
- Four year olds used to steal their parents' data
- An acceptable use policy for your kids
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
advertisement
