Microsoft talks up countermeasures to fend off IE attacks

By Gregg Keizer, Computerworld |  Security, ie, Microsoft Add a new comment

Microsoft warned users of Internet Explorer 7 (IE7) late Wednesday that attackers are actively exploiting a critical bug in the browser, and urged them to take countermeasures in lieu of a patch.

In a late-Wednesday security advisory, Microsoft officially acknowledged the flaw. "We are aware only of limited attacks that attempt to use this vulnerability," the company said, adding that users running IE7 in Windows XP , Windows Vista , Windows Server 2008 and Windows Server 2008 are at risk.

As is its practice, however, the company was vague about whether it would patch the problem, and if so, when. "On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through a service pack, our monthly security update release process, or an out-of-cycle security update, depending on customer needs."

The last time that Microsoft went off its usual once-a-month security update schedule was in late October, when it issued an emergency patch for a bug in Windows that was also being exploited in the wild.

In one way, Microsoft downplayed the threat posed by the IE7 bug, which independent researchers have said is in a browser rendering component , and is triggered by misuse of the HTML "span" tag.

"Our investigation of these attacks so far has verified that they are not successful against customers who have applied the workarounds listed in this advisory," Microsoft said. "Additionally, there are mitigations that increase the difficulty of exploiting this vulnerability."

The company spelled out three things IE7 users can do to protect themselves:

Set "Internet" and "Local internet" security zones to "high." To do that, users must select "Internet Options" from the Tools menu, click the Security tab, click on "Internet," then move the slider to the "High" setting. Repeat for "Local intranet." Click OK.

Disable Active Scripting. Choose "Internet Options" from the Tools menu, click the Security tab, click the "Internet" icon and then the "Custom level" button. In the ensuing dialog, under the "Scripting" section, in the "Active scripting" item, click "Disable," then OK.

Enable DEP (data execution prevention). Select "Internet Options" from the Tools menu, click the Advanced tab, then check "Enable memory protection to help mitigate online attacks." Click OK.

Although multiple exploits have surfaced, all are effective against only IE7. Researchers, including those at Microsoft, are still investigating whether the older IE6 also contains the same vulnerability.

"The information posted in Microsoft's security advisory is what the company knows to be true at this time, [but] Microsoft continues to investigate this vulnerability," a company spokesman replied in an e-mail when asked whether Microsoft had found a similar bug in IE6. "If Microsoft can confirm new information based on its ongoing investigation, it will update the security advisory as necessary."

Mary Landesman, a senior security researcher at ScanSafe Inc., a San Francisco-based security company, noted that if IE6 does turn out to be vulnerable to attack, users can protect themselves by switching on DEP in the operating system.

Because IE6 lacks a DEP setting, users running Windows XP, both Service Pack 2 (SP2) and SP3, must turn it on in the operating system instead. To do so, right-click "My Computer," select "Properties" from the ensuing menu, then click the "Advanced" tab. Under the "Performance" section, click the "Settings" button, then the "Data Execution Prevention" tab. Select the "Turn on DEP for all programs and services except those I select:" and click OK.

IE8, which is in Beta 2 at the moment, enables DEP by default.

Also today, researchers at iDefense, a security intelligence firm owned by VeriSign Inc. , said that the first exploit made public -- which targets Windows XP and Server 2003 systems -- was mistakenly released by Chinese security analysts.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question