Tuesday, 24 November 2009 15:14

IE6 and IE7 vulnerable to latest flaw; IE8 immune

Rate this item
(0 votes)

Microsoft has confirmed reports of a new vulnerability that affects both Internet Explorer 6 and Internet Explorer 7, but not Internet Explorer 8.

Microsoft has issued Security Advisory 977981 in regard to public reports of a vulnerability that exists as an invalid pointer reference of Internet Explorer. Under certain conditions, it is possible for a CSS/Style object to be accessed after the object is deleted, and thus, if Internet Explorer attempts to access the supposedly freed object, it can end up running attacker-supplied code. IE6 SP1 on Windows 2000 SP4, as well as IE6 and IE7 on supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 are affected. Microsoft notes that IE 5.01 SP4 and IE8 on all supported versions of Windows are not affected, but of course IE6 and IE7 still account for over 40 percent of the browser market.

Exploit code for the flaw was first posted late last week on the BugTraq mailing list (see either securityfocus.com or seclists.org). Microsoft noted its concern that this new report of the vulnerability was not responsibly disclosed, potentially putting computer users at risk, but that it is not aware of any attacks that try to use the reported vulnerability against IE6 and IE7. Redmond says it is actively monitoring the situation and may provide a security update on an upcoming Patch Tuesday or an out-of-cycle patch once it is ready. The next Patch Tuesday is scheduled for December 8, 2009, but we’re not likely to see a patch out that soon.

In addition to the latest version being unaffected by this vulnerability, Microsoft offered four other mitigating factors:

  • Protected Mode in IE7 on Windows Vista limits the impact of the vulnerability.
  • By default, Internet Explorer on Windows Server 2003 and Windows Server 2008 runs in a restricted mode that is known as Enhanced Security Configuration. This mode sets the security level for the Internet zone to High and so is a mitigating factor for websites that you have not added to the Internet Explorer Trusted sites zone.
  • An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
  • By default, all supported versions of Microsoft Outlook, Microsoft Outlook Express, and Windows Mail open HTML e-mail messages in the Restricted sites zone, which should mitigate attacks trying to exploit this vulnerability by preventing Active Scripting and ActiveX controls from being used when reading HTML e-mail messages. However, if a user clicks a link in an e-mail message, the user could still be vulnerable to exploitation of this vulnerability through the Web-based attack scenario.

Microsoft also offered three workarounds for the new IE flaw. The first one explains how to set the Internet and Local intranet security zone settings to “High” so that the browser prompts the user before running ActiveX Controls and Active Scripting in these zones. The second one details how to configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone. Finally, the last one suggests enabling Data Execution Prevention (DEP) for IE6 SP2 or IE7. All three are explained with step-by-step instructions in the security advisory and can be done by simply changing settings in Internet Explorer.

In December 2008, Microsoft released an out-of-band security update for Internet Explorer and encouraged all users to run Windows Update or Microsoft Update to download the fix.

Leave a comment

Make sure you enter the (*) required information where indicated.
Basic HTML code is allowed.

Get a Quote
   
 
Click below to get Live Support Now
 

Oct, 31 2011

  Benefits of Using IT Support Company on a Flat Rate  


Sep, 09 2011

  Finding Computer Support Company for Nursing Facility  


Sep, 07 2011

  vSphere 5 Is VMware's Jump into Data Storage Virtualization  


Aug, 17 2011

  Bomgar Analysis and Review at TTIG  


Jul, 22 2011

  What Do You Know About Your Backup?  


Jul, 22 2011

  Geopolitical Inputs Into Cloud Computing Decision  


Mar, 08 2011

  A Popular Hosting Company, Codero, is Attacked With a DDoS From China  


Feb, 13 2011

  Stuxnet. A War Among Nations – Why Should IT Managers Care?  


Aug, 11 2010

  AT&T and Verizon Design New Payment System to Compete with Credit Cards  


Jul, 11 2010

  Will The Perfect Citizen Protect?  


Jul, 04 2010

  Copper T1 Is One Way To Go, Microwave Wireless Is Another!  


Jun, 24 2010

  Don't Jump for the iPhone 4 Until You Look At Droid X  


Jun, 20 2010

  Google Apps Market Place  


Jun, 09 2010

  Microsoft and Adobe Release Critical Security Patches  


Feb, 08 2010

  Annoying explorer.exe taking up CPU fix  


Feb, 07 2010

  Biggest Mistakes Companies Make in Selecting an IT Provider or IT Company  


Jan, 26 2010

  Google Chrome Is Fast and Now Has Bookmark Sync and Extensions  


Jan, 26 2010

  Cyber Warfare Is Here - What Does That Mean For You?  


Jan, 25 2010

  Web Remote Workplace Doesn't Work with Internet Explorer - IE 8  


Dec, 09 2009

  Funny Windows 7 and Chrome Interaction  


Nov, 24 2009

  IE6 and IE7 vulnerable to latest flaw; IE8 immune  


Jul, 23 2009

  Denial of Service Attacks  


Oct, 23 2009

  New Microsoft Vulnerability Blacklisted by Firefox  


Oct, 19 2009

  New Vulnerabilities That Concern YOU!  


Aug, 01 2009

  Adobe Product Fixes Available Now  


Jul, 27 2009

  Critical Exploit Found in Adobe Products  


Jul, 08 2009

  Cyber Security And Your Family  


 

Backup Solutions

The TTIG managed backup solution is a safety net on steroids, providing daily motoring and confirmation of the integrity and safety of all data under management. Step into controlled environment of TTIG Disaster Recovery and Data Redundancy Planning.

+ Learn More
 

Security Solutions

In today's world of data vulnerability, we provide your organization with the best security practices, continuous risk assessments and even managed security monitoring when necessary. Our approach is comprehensive, our solutions increase security. Control Your Data!

+ Read More
 

Managed IT Services

We centralize our IT Management Process to ensure complete situational awareness through continuous client communication, network monitoring, alerting, and preventative network maintenance. Managed services allow for reduction of downtime through a highly proactive

+ Read More