Pavlov Scope

2006 March 23

IE - Yet ANOTHER critical unpatched flaw

Filed under: ITSec — Kev Frey @ 17:20:31

Here we are again – another unpatched IE bug has just been announced. This one is similar to the issue last Dec. 2005 (described here External Link) in that disabling Active Scripting – Internet Explorer’s JavaScript engine – prevents the flaw from being exploited.

The official “word” from Microsoft is here External Link, but the gist for non-technical users out there is that this is a remotely exploitable (meaning, your computer can be compromised without having local access to your physical computer) and critical flaw that can allow an attacker, virus, or spyware (etc.) to run programming code on or infiltrate your computer or network.

There is a exploit code now publicly available that utilizes this flaw, so it is only a matter of time (short amount of time) before spyware, adware External Link, phishers External Link, virus writers, and hackers adapt the code for more nefarious purposes.

Microsoft has not issued a patch yet, but is working on one now, so stay tuned for an “out of cycle” patch to be released. I will let you know here as soon as I am notified.

In the meantime, always know that there are other browsers to use when IE has flaws like this – I recommend either Firefox External Link (with the Adblock, NoScript, and Fasterfox extensions External Link) and Opera External Link (now version 8.53).

Avoid using Internet Explorer for the next few days if at all possible. Once I’ve installed and tested the forthcoming patch, I’ll post on this blog.

_____________________________________________________________
KevFrey

kevfrey@gmail.com
.     .    .   .  . .. .  .   .    .     .
 Abbreviation and acronyms – the first indications of acceptance.

Powered by Bleezer

Leave a Reply

You must be logged in to post a comment.