Flaw found that affects every Windows machine

By
Follow google news

No server-side workaround yet.

Microsoft on Friday warned that all Windows desktops and servers were vulnerable to a script-handling flaw that could allow an attacker to spoof information displayed in a browser.

Flaw found that affects every Windows machine

The disclosure was made in response to the publishing of a proof-of-concept distributed on the internet which uncovered problems in the way Windows handles MIME-formatted requests.

Maliciously-crafted script that runs on the client side could “spoof content, disclose information, or take any action that the user could take on the affected Web site on behalf of the targeted user,” Microsoft warned.  

“The impact is the same a server-side cross-site scripting issue, but the vulnerability lies in the client,” Microsoft explained.

All Windows-run web services that interact with users via input fields are vulnerable, according to Microsoft.

While Redmond has identified a relatively simple client-side work-around, the temporary fix for servers is more complicated, prompting Microsoft to call in Google and other service providers to help solve the problem.

Without a patch or a server side work-around, Microsoft advised web site operators to tell customers to lock down the MHTML protocol handler.

More information can be found here.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

NSW Treasury staffer allegedly exfiltrated 5600 sensitive documents

NSW Treasury staffer allegedly exfiltrated 5600 sensitive documents

Cloud deployment firm Vercel breached, advises secrets rotation

Cloud deployment firm Vercel breached, advises secrets rotation

Dead cars tell tales by storing data that's never wiped

Dead cars tell tales by storing data that's never wiped

Log In

  |  Forgot your password?