Two New IE Flaws Discovered

By Ed Oswald | Published June 30, 2006, 1:30 PM

Security researchers have discovered two new flaws in Internet Explorer. While proof of concept code is available for both, there are no known exploits of either flaw.

The first involves a cross-site scripting issue where an attacker could view information in an open browser window from another that is visiting a malicious site. However, researchers called the issue less serious than the other flaw, saying it requires user interaction, and sensitive data in other browser windows.

"Several handlers have spent a little more time validating this particular issue and while it is a subtle exploit and rated a lower level risk, this issue has raised some of our neck hairs," Bojan Zdrnja of the SANS Internet Storm Center said on the company's Web site.

Adrian Stone at the Microsoft Security Research Center confirmed that the company was looking into the issue. "So far we're not aware of any attacks attempting to use vulnerability or any customer impact, but we wanted to let everyone know we're investigating," he said.

At one time, the above flaw was thought to affect Mozilla Firefox as well, however further testing by SANS found that is not the case. Additionally, the group found that Internet Explorer 7 is also immune to the vulnerability.

A second more serious flaw involves how HTA applications are handled. A user could be tricked into opening a malicious file, which in turn could execute code. The file would need to be accessed through SMB or WebDAV in order for the issue to be exploited.

"The currently available version of PoC that was published is limited in that it requires the user to double click on an icon to execute a potentially malicious payload, but we can expect to find creative use of this exploit in the wild very soon," Zdrnja said. "The workaround for this appears to be disabling active scripting."

Microsoft said it was investigating the HTA flaw as well.

Comments

View comments by with a score of at least

AMUST 1-Defender
(http://amustsoft.com/1-defender/)
Great utility that allows to reduce or eliminate the risks by allowing you to run Internet Explorer in SafeBrowse™ Mode, which limits the Internet Explorer and restricts it from performing all operations that may significantly impact your system. Moreover, it gives user a luxury of choice how to run IE (protected or not) for a given task.

Score: 0

|

Seriously: Why bother? I mean, there are other browsers out there with reduced or minimal threats. Anyone still using IE is getting what they deserve.

Score: 0

|

Why should MS be obligated to fix anything we've already paid for? The fact that they do respond and release fixes is a good step for the evil empire. I'm a FF user, but IE7 does look very nice. IE7 borrows tabs from FF, but beta 3 seems faster.

Score: 0

|

no way!

Score: 0

|

If the hundreds of thousands of hackers turned their attention to firefox, opera or any other browser instead of IE, then those other browsers would have faults found as well. IE is a target by so many they have more FOUND faults.

Score: 0

|

So what? As a Firefox user, why should I care why it is more secure than IE? As long as it is, I will keep using it. If it becomes less secure, because of an increase in users or for any reason, I can reevaluate my decision and use something else.

Score: 0

|

Exactly why I use firefox - "IE is a target by so many"

Score: 0

|

Score: 0

|

OPERA OPERA OPERA!!!

http://www.opera.com

Well what do you know, I can make a pointless comment too ;)

Score: 0

|

sux

Score: 0

|

This issue is not affected in IE7

Score: 0

|

LYNX LYNX LYNX!!!

http://lynx.browser.org/

Score: 0

|

OFF BY ONE!! OFF BY ONE!! OFF BY ONE!!!

Me too!

http://offbyone.com/offbyone/

Best.

Browser.

Evah! ;)

Score: 0

|

Microsoft's IE has always had flaws and always will. I took a test drive of IE 7. It is not user friendly and is just as slow as 6
Personally I like firefox and the old netscape for surfing the web.

Score: 0

|

IE slow? in term of what? How is IE 7 not user friendly?

I am a FF user too, and I think FF is slower than IE, but I like FF because it's safer than IE and I customize it with extensions the way I like.

Score: 0

|

I think IE 7 appears un-user friendly because they rearranged the program in so much a way that it will initially alienate current IE 6 users.

There are other non-user friendly aspects to the program. When you press ctrl+t to create a new tab, it doesn't focus the keyboard in the address bar, thus taking away the point of using a keyboard shortcut to save time. (This will probably be fixed in the final version though). Also, you can't hide the tab bar when there's only one tab open. They try to make it more useful by adding other buttons to that bar as well, but to me, it still feels like it's wasting space.

As for speed - I've always considered it a non-issue. Maybe that's because my computer itself is fast enough to make any difference negligable? This is so much so that I forget, when trying to quote a fact, which browser is supposively the fastest.

Score: 0

|

Rendering wise, IE is a bit faster. But then again, if you put into account the lack of adblock for IE, I find Firefox loading my content to be much faster.

And Firefox is faster than IE7 in terms of tabs, program navigation etc. It's just more responsive. IE7 beta 3 made some progress in that area though. We'll see.

Score: 0

|

i have to agree with taht adding buttons to the tab bar comment, i havent tried IE7 but from then screenshots ive seen the tab bar looks really cramped, and really large too (though i assume you can change that by choosing small icons or something)

with firefox, and my resolution, i can have 9 or more tabs open and see enough of the titles to know what each one is, why need thumbnail? useless gimmik

Score: 0

|

Actually, thumbnail viewing comes in pretty handy dumba**. Just because you have no use for it, doesn't mean it ain't useful. Don't make destructive comments that could put off users from wanting to experiment with a new feature just because *you* find no use for it (you just branded it a useless gimmick without even giving good reasons). For your information, the feature helps to expand multiple tab browing experience.

Score: 0

|

Every software will have some flaws. What matters is when it is found and how quick its being fixed. Hope M$ will soon have a patch for it.

Score: 0

|

That's nothing new at all about internet explorer, They're alway finding flaws in it.

Score: 0

|

IE6 is years old. Of course they are going to find holes. MS needs to push IE7 out the door soon.

Score: 0

|

Yes because, no one will find holes in IE7 - it will be perfect!

Score: 0

|

Much like was thought of firefox huh? We saw how quickly they extinguished that candle.

Score: 0

|

funny
firefox:
http://secunia.com/product/4227/
Currently, 4 out of 33 Secunia advisories, are marked as "Unpatched" in the Secunia database.

Internet Explorer:
http://secunia.com/product/11/
Currently, 20 out of 104 Secunia advisories, are marked as "Unpatched" in the Secunia database.

Score: 0

|

And does exploit code exist for any of the IE ones just like the firefox ones? No, so these arent serious. No reports of anyone affected, no damage done. So, your point?

Score: 0

|

Point: Firefox has only been out for one or two years. IE has been out for YEARS AND YEARS.

Firefox SHOULD logically have more exploits because IE has had more time to be patched...

... but instead a repeatedly patched IE has far more holes than a newer, less tried and tested browser.

Score: 0

|

Percentage wise in the same time period FF has more issues then IE does

Score: 0

|

Dont forget LESS USED

Score: 0

|

Only two?

Thats a pretty good week for Microsoft.

Score: 0

|

Yeah, but they have 20 unpatched. Besides, a huge huge portion of users in the world don't have a genuine version of Windows XP. They won't be able to upgrade to IE7.

Score: 0

|

and obviously those 20 unpatched holes arent very serious otherwise code would exist to exploit them.

Score: 0

|

Beta Software +1
Hackers 0

Score: 0

|

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.

PDC 2009: Microsoft cares about Web browser performance

The effort to give users of the world's dominant Web browser the impression of quality, is a personal one for the man who leads that battle.

Nokia re-affirms its commitment to Symbian, sort of

Maemo won't necessarily be replacing Symbian in the Nokia N-Series, but that's definitely a place where it will be found.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

AOL's spinoff from Time Warner to shed 2,500 jobs

As AOL moves toward become an independent company again, it will cut nearly a third of its workforce.

Gartner: SMS-based money transfer will be bigger than mobile browsing, search

Gartner issues its predictions for the 10 things our phones will be doing in 2012.

Don't forget to upgrade to Firefox 3.6 beta 3 today

Mozilla has released the latest beta its Firefox 3.6 browser software, just over one week after beta 2.