Attackers take aim at IE7 flaw

 

Microsoft is warning users to avoid suspicious websites and emails after attacks were reported on an unpatched flaw in Internet Explorer 7.

The company would not provide exact figures, but said that a "limited number " of attacks had been reported.

The attacks target a vulnerability in IE7's handling of the uniform resource indicator (URI) commands used by browsers to launch third-party applications.

Microsoft disclosed the vulnerability on 10 October, explaining that it arises when the browser fails to check malformed URI instructions in Windows XP and Server 2003. Windows Vista is not believed to be vulnerable.

Security firm Secunia rated the vulnerability as 'highly critical', the fourth of its five severity levels.

Microsoft Security Response Center team member Bill Sisk told users in an article posted to a company blog that a fix is in development, but could take some time owing to the nature of the vulnerability.

Executing an attack on the vulnerability involves using the 'ShellExecute' command that Windows calls up to load applications.

Because the component is such a vital part of Windows, Sisk said that Microsoft is taking extra care to ensure that a security fix will not damage the operating system.

In the meantime, Microsoft and Secunia recommend that users avoid untrusted or suspicious links and websites and avoid opening attachments in unsolicited emails.

Copyright ©v3.co.uk


Attackers take aim at IE7 flaw
Tags
 
 
 
 
 
Top Stories
Windows 8: Under the hood
Part One of iTnews' enterprise guide to Windows 8.
 
iTnews on tour: The Executive Summit Series
Join us in Sydney and Melbourne to meet Australia's tech leaders.
 
Meet Westpac's new technology leaders
Engineering realigned under CTO.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Was your 2012 IT budget...




   |   View results
Cut by less than ten percent?
  15%
 
Cut by more than ten percent?
  34%
 
Flat
  27%
 
Increased by less than ten percent?
  7%
 
Increased by more than ten percent?
  16%
TOTAL VOTES: 409

Vote
Will you still use DropBox and other cloud storage in the wake of the Megauploads saga?

   |   View results
Yes
  65%
 
No
  35%
TOTAL VOTES: 303

Vote