Microsoft investigating new Internet Explorer flaw

By
Follow google news

Microsoft said it is looking into one of the newly reported flaws in Internet Explorer (IE) on Wednesday.

The Redmond, Wash., company is aware of the reported flaw and is investigating it, Adrian Stone of the Microsoft Security Response Center said on a company blog. Microsoft is not aware of any attacks taking advantage of the vulnerability or any customer impact, he said.


"What we know at the moment is that the vulnerability can be attacked through Internet Explorer and requires user interaction on the page before the attack can occur," Stone said.

Two new reported flaws for IE, along with their proof-of-concept code, were published on Tuesday on the Full Disclosure mailing list, according to the SANS Internet Storm Center.

The first flaw is located in the use of HTA applications and could be exploited to trick a user into opening a malicious file, which has to be accessible through server message block or a remote site, according to a SANS advisory.

The second flaw is located in the handling of the object.documentElement.outerHTML property, according to SANS, and it can allow an attacker to retrieve remote content in the context of the web page currently being viewed, according to the advisory.

Microsoft’s next scheduled Patch Tuesday release is on July 11. Earlier this month, the company released 12 new security fixes as part of the biggest Patch Tuesday in over a year.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

National photo licence recognition system set to go live in 2025

National photo licence recognition system set to go live in 2025

Hackers using F5 devices to target US gov networks

Hackers using F5 devices to target US gov networks

Qantas says customer data released by cyber criminals

Qantas says customer data released by cyber criminals

Austrade to replace its data centre core network

Austrade to replace its data centre core network

Log In

  |  Forgot your password?