Indian researcher detects remote access flaw in Internet Explorer

By
Follow google news

A researcher today unveiled an unpatched and unconfirmed vulnerability in Internet Explorer (IE) that could allow an attacker remote access to victims' local files.

Indian researcher detects remote access flaw in Internet Explorer
According to an advisory posted on XDisclose, the "critical" flaw is related to the way that IE processes different HTML tags, such as "img," "script," "embed," "object," "param," "body" and "input."

The bug was discovered by Rajesh Sethumadhavan, a research engineer from India.

"By using the file protocol along with [these]tags, it is possible to access victims’ local files," according to the XDisclose advisory.

The vulnerability exists in IE6 and is possible in other versions of the browser. For success, an attacker must dupe a PC user into visiting a website containing the malicious code, according to the advisory.

A Microsoft spokesman told SCMagazine.com today that he was trying to confirm the report with researchers from the company’s Security Response Center.

The revelation came less than a week after Redmond issued a dozen patches addressing 20 vulnerabilities.
Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Labor bets on agency to monitor AI companies

Labor bets on agency to monitor AI companies

Startup finds flaws in popular VoIP products

Startup finds flaws in popular VoIP products

JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack

JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack

Bendigo Bank taps Google Cloud for first major AI project

Bendigo Bank taps Google Cloud for first major AI project

Log In

  |  Forgot your password?