• On MovieTome: See the TRAILER for TERMINATOR 4!

August 29, 2005 10:30 PM PDT

Microsoft investigates another IE flaw report

A new, unpatched flaw in Internet Explorer could let miscreants surreptitiously run malicious code on Windows PCs, according to the discoverer of the bug.

The problem affects Internet Explorer 6--the latest version of Microsoft's Web browser--on computers running Windows XP with Service Pack 2 and all security patches installed, Tom Ferris, an independent security researcher in Mission Viejo, Calif., said in an interview Monday. Other versions of Windows and IE may also be vulnerable, he said.

The security hole allows for "full-blown remote code execution," Ferris said. "If a user browses to a bad Web site, malicious software can be installed on their PC without their knowledge."

Ferris claims credit for discovering the problem and said he informed Microsoft of the flaw on Aug. 14. He reported some basics of the bug on his Security Protocols Web site Saturday, but he is not sharing more details to prevent information from getting into the wrong hands.

A Microsoft representative late Monday confirmed the company received Ferris' report. The Redmond, Wash., software giant can't confirm whether the flaw exists, but it is investigating the report, the representative said. "At this time, there are not any attacks, and there are not any risks" to users, she said.

Ferris said he provided Microsoft with details on the bug, including computer code to prove the existence of the problem. On his Web site, Ferris shows a screen shot of a crashing IE 6 Web browser, which he said was caused by the same bug.

Upon completion of the investigation, Microsoft will take the appropriate action to protect users, the representative said. This may include providing a security update through its monthly patch release or providing an out-of-cycle security update, she said.

There are several unpatched vulnerabilities in IE 6, according to Secunia. The security monitoring company has issued 69 alerts on the Web browser since 2003; almost one-third of those security bugs remain unpatched, according to Secunia's Web site. Secunia has yet to put out an advisory on this latest IE security issue.

Ferris has found bugs in Microsoft software before. Earlier this month, Microsoft credited him with reporting a bug in a Windows feature called the Remote Desktop Protocol that could allow an attacker to remotely restart Windows systems.

Ferris recommends people pick a different Web browser or use caution when surfing the Web to protect against any exploitation of the latest IE flaw and other browser bugs. Microsoft, as always, urges users to apply all available software patches and run updated security software.

See more CNET content tagged:
Microsoft Internet Explorer 6, Microsoft Internet Explorer, bug, malicious code, security

Add a Comment (Log in or register) 56 comments (Showing first 20 comments)
Terrible news
by August 29, 2005 10:46 PM PDT
Anyway, switch to Firefox is the best and final choice.
Reply to this comment View reply
Terrible news
by August 29, 2005 10:46 PM PDT
Anyway, switch to Firefox is the best and final choice.
Reply to this comment View reply
A possible way to make it worse
by amadensor August 30, 2005 3:13 AM PDT
Do not forget that Windows uses IE to render all sorts of other things. This means that perhaps a carefully crafted email or document could also cause this to happen.
Reply to this comment
A possible way to make it worse
by amadensor August 30, 2005 3:13 AM PDT
Do not forget that Windows uses IE to render all sorts of other things. This means that perhaps a carefully crafted email or document could also cause this to happen.
Reply to this comment
HAHAHAHAHA Can I laugh at Windows users much more?
by educateme August 30, 2005 4:04 AM PDT
You guys must feel like pincushions by now, no other product in
history has taken so much out of society's pockets, and ruined
their days off fixing more crap. The solution is not to stop using
IE, it is to STOP using Windows. Microsoft sucks, can I say it any
louder for you poor slobs that cant say "SH*T" with a
mouthful....WINDOWS SUCKS, get over your lame professions
that this OS is Ok, and that smart users "patch" their systems.
Have you not learned by now that its not going to end. Lets see,
I patched my Apple PowerBook once or twice a month, does it
get bitten weekly by bugs, viruses, worms, or trojans NOPE!!! In
this world, trojans are for when youre having "safe" fun, but for
PC losers its the sign of bad birth control, Bill Gates birthed a
"lemon" on the world. Go ahead, admit it, you bought junk.
Hahahaha. You really ought to buy a Macintosh and learn what
stability and trouble free computing is all about. Poor suckers.
Bill Gates loves you though, I am sure he's got a big present for
you this holiday, keep waiting for it, its in the mail.......;-)
Reply to this comment View all 6 replies
HAHAHAHAHA Can I laugh at Windows users much more?
by educateme August 30, 2005 4:04 AM PDT
You guys must feel like pincushions by now, no other product in
history has taken so much out of society's pockets, and ruined
their days off fixing more crap. The solution is not to stop using
IE, it is to STOP using Windows. Microsoft sucks, can I say it any
louder for you poor slobs that cant say "SH*T" with a
mouthful....WINDOWS SUCKS, get over your lame professions
that this OS is Ok, and that smart users "patch" their systems.
Have you not learned by now that its not going to end. Lets see,
I patched my Apple PowerBook once or twice a month, does it
get bitten weekly by bugs, viruses, worms, or trojans NOPE!!! In
this world, trojans are for when youre having "safe" fun, but for
PC losers its the sign of bad birth control, Bill Gates birthed a
"lemon" on the world. Go ahead, admit it, you bought junk.
Hahahaha. You really ought to buy a Macintosh and learn what
stability and trouble free computing is all about. Poor suckers.
Bill Gates loves you though, I am sure he's got a big present for
you this holiday, keep waiting for it, its in the mail.......;-)
Reply to this comment View all 6 replies
Simple solution for Windows Userrs...
by Earl Benser August 30, 2005 5:02 AM PDT
... QUIT USING IE !!!!

If you haven't learned by now that IE is near the root of all Windows
disasters, learn it now. Delete IE functionality (You can;t get rid of
the code due to MS's Marketing driven misdesign of the WIndows
OS) and move to a real browser.

It really doesn't take any skill or experience to make the shift.
Reply to this comment View reply
Simple solution for Windows Userrs...
by Earl Benser August 30, 2005 5:02 AM PDT
... QUIT USING IE !!!!

If you haven't learned by now that IE is near the root of all Windows
disasters, learn it now. Delete IE functionality (You can;t get rid of
the code due to MS's Marketing driven misdesign of the WIndows
OS) and move to a real browser.

It really doesn't take any skill or experience to make the shift.
Reply to this comment View reply
I just came to see...
by Harfeld Bilgewing August 30, 2005 6:31 AM PDT
What all the trolls were posting.
Reply to this comment View reply
I just came to see...
by Harfeld Bilgewing August 30, 2005 6:31 AM PDT
What all the trolls were posting.
Reply to this comment View reply
Ambiguous "Chicken Little" Info at best...
by fred dunn August 30, 2005 8:14 AM PDT
There is a flaw in XXXX product but I can't tell you what it is because if I did I'd have to kill you. Come on, if you're not going to give details on the flaw then why publish that there is a flaw? Is there really a flaw? You don't know yet but yet your publishing an ambiguous story. Do some research and then publish otherwise it's just rumor.
Reply to this comment
Ambiguous "Chicken Little" Info at best...
by fred dunn August 30, 2005 8:14 AM PDT
There is a flaw in XXXX product but I can't tell you what it is because if I did I'd have to kill you. Come on, if you're not going to give details on the flaw then why publish that there is a flaw? Is there really a flaw? You don't know yet but yet your publishing an ambiguous story. Do some research and then publish otherwise it's just rumor.
Reply to this comment
Does news.com copy/paste this same story weekly?
by aabcdefghij987654321 August 30, 2005 9:23 AM PDT
Need I say more?
Reply to this comment View all 2 replies
Does news.com copy/paste this same story weekly?
by aabcdefghij987654321 August 30, 2005 9:23 AM PDT
Need I say more?
Reply to this comment View all 2 replies
Security improving
by bp2004 August 30, 2005 5:30 PM PDT
The new exploit only allows malicious code to be run on your computer? Isn't this an improvement?

Usually its been "this exploit could allow an attacker to take complete control of your computer"

Security is improving.


<end sarcasm>
Reply to this comment
Security improving
by bp2004 August 30, 2005 5:30 PM PDT
The new exploit only allows malicious code to be run on your computer? Isn't this an improvement?

Usually its been "this exploit could allow an attacker to take complete control of your computer"

Security is improving.


<end sarcasm>
Reply to this comment
I can provide them with a bunch of screenshots...
by fred dunn August 31, 2005 10:02 AM PDT
of IE crashing, So what.
Reply to this comment
I can provide them with a bunch of screenshots...
by fred dunn August 31, 2005 10:02 AM PDT
of IE crashing, So what.
Reply to this comment
 See all 56 Comments >>
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right