Microsoft Investigating New IE6 Flaw

By Nate Mook | Published August 30, 2005, 10:58 AM

Microsoft said it is investigating a report of a new potentially critical flaw discovered in Internet Explorer by security researcher Tom Ferris. The problem affects fully patched Windows XP SP2 systems running IE6, and could lead to remote code executation.

Ferris, who has been credited by Microsoft as finding a security vulnerability in the Remote Desktop Protocol, says he reported the issue to Microsoft on August 14. Ferris is not sharing any specifics of the flaw in order to keep users safe while Microsoft develops a patch, but he has posted a screenshot of IE crashing from the bug.

Comments

View comments by with a score of at least

As I WATCH CNN REPORTS CONCERNING THE KATRINA DISASTER AND VIEW THEIR USE OF GOOGLE EARTH TO ILLUSTRATE THE DEVASTATION I AM REMINDED THAT SOFTWARE DEVELOPMENT OUGHT TO GO BEYHOND THE BOTTOM LINE. MICROSOFT CANNOT DEVELOP A SIMPLE BROWSER SUCH AS IE 6.WHAT CAN WE EXPECT FROM VISTA????????????????????????????????????????????

Score: 0

|

IE has a flaw, wow this is a first. I can't believe this happend to Internet Explorer. Its SOOO safe. I don't know how this could have happend. HAHA

Score: 0

|

Thank you Tom! Finally someone doing it the right way! He found the exploit, contacted MS and is now waiting for them to fix it before going into details about it.

Score: 0

|

Most researchers do it that way. The problem is that not everyone will go ahead and install the patch causing problems like zotob.

Score: 0

|

zotob was infecting less than 4 days from release of a patch. If you know large corporate networks you know how hard it is to test patches across your enterprise. Had they patched early and it broke their network would they then be free from criticism?

The solution is immediate testing in lab environments, then scales releases across your WAN by specific groups. CNN was up and running fine the next day, btw.

Score: 0

|

CNN wouldn't have had any problems if they had a decently secure network.

Score: 0

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.