IE 6 and 7 Bug Allows for Attacks via Poisoned Sites

By Erik Larkin, PC World |  Security, ie6, ie7

A new security hole in Internet Explorer 6 and 7 can be targeted via code on a poisoned Web site, Microsoft warned today. A successful attacker could install malware on a victim PC or run any other remote command.

The invalid pointer reference bug, described in Microsoft Security Advisory 981374, is already being hit by targeted attacks, according to Microsoft. The company only released a warning, rather than a patch to go along with its regularly scheduled Patch Tuesday. There isn't yet any fix or real workaround, but Internet Explorer 8 is not affected by the bug.

Microsoft also says that IE running under Protected Mode on Vista or Windows 7 will help mitigate the threat, and that the default IE configuration on Windows Server 2003 and 2008 also offers protection. For more details, see the company's MSRC post.


Originally published on PC World |  Click here to read the original story.
Join us:
Facebook

Twitter

Pinterest

Tumblr

LinkedIn

Google+

Answers - Powered by ITworld

ITworld Answers helps you solve problems and share expertise. Ask a question or take a crack at answering the new questions below.

Join us:
Facebook

Twitter

Pinterest

Tumblr

LinkedIn

Google+

Ask a Question