IE open to hackers
IE open to hackers

IE plagued by 'extremely critical' flaws

Security firm advises get another browser

Written by Iain Thomson

Millions of Internet Explorer 6 users are at risk from three "extremely critical" security holes that give hackers open access to PCs running the browser - even if Windows XP Service Pack Two has been installed.

The first issue centres on the browser's drag and drop capability, which does not validate new files correctly. This means that, potentially, a document downloaded from a web page using drag and drop may contain malicious code.

The other problems affect all Windows systems, including those protected by Local Computer zone lockdown that comes with SP2. The first allows specially designed (.hhk) files to be used to include malicious code on systems and the second stems from a zone restriction error that could allow code to be downloaded form web sites involuntarily.

At least one of the flaws was reported to Microsoft last year but no patches have so far been made available.

Security firm Secunia has released an advisory warning that the holes are "extremely critical" and recommends users dump IE and use an alternative browser.

"

Although hundreds of millions of dollars have been spent on securing SP2, perfection is impossible. Through the joint effort of Michael Evanchik and Paul from Greyhats Security a very critical vulnerability has been developed that can compromise a user's system without the need for user interaction besides visiting the malicious page," Secunia warned in a statement.

Tags:

reader comments

related articles

Neil Barrett

Bot armies exploit tragedy

The Tragedy of the Commons provides important lessons for internet users 27 Jan 2005

 

Windows open to critical vulnerabilities

Time to get patching 12 Jan 2005

Researchers spot XP SP2 security weakness

IE drag and drop feature could be exploited by hackers 20 Aug 2004

Microsoft warns of three critical IE flaws

Hackers could take complete control of an affected system 02 Aug 2004

Microsoft offers IE flaw workaround

Browser fix 'improves system resiliency' but does not patch the flaw 05 Jul 2004

Cert suggests firms exit IE

Internet Explorer is a hazard in itself, according to the US security advisory body 05 Jul 2004

Microsoft pushes out 17 security fixes

'Critical' patches for Windows, Office and Internet Explorer 13 Feb 2008

Microsoft warns of Safari for Windows hole

Hackers could 'carpet bomb' the user's desktop 05 Jun 2008

SuSE patches 'highly critical' Java flaw

Remote system access possible unless update is applied 18 Oct 2007

related whitepapers

today's top stories

Computing launches all-new IT jobs site

Updated Computingcareers.co.uk provides enhanced feature for jobseekers 14 Oct 2008

Q&A: BT Business head of SaaS, Chris Lindsay

BT's head of software-as-a-service explains the benefits of the on-demand delivery model and how the current economic downturn could force firms to re-evaluate how they buy software 14 Oct 2008

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Are you worried about your job prospects in IT over the next 12 months?

Are you worried about your job prospects in IT over the next 12 months?

Will the economic crisis affect your job prospects?

Previous poll results

Latest audio and video articles

Remote workerVideo

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Latest in-depth articles

BT TowerAnalysis

Q&A: BT Business head of SaaS, Chris Lindsay

BT's head of software-as-a-service explains the benefits of the on-demand delivery model and how the current economic downturn could force firms to re-evaluate how they buy software 14 Oct 2008

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Advertisement

Primary Navigation