• On MovieTome: Megan Fox on TRANSFORMERS 2!

September 8, 2003 2:59 PM PDT

Security firm: IE patch does not work

Related Stories

Microsoft warns of critical IE flaws

August 20, 2003

One year on, is Microsoft 'trustworthy'?

January 16, 2003
A patch released by Microsoft to fix a critical security vulnerability in its Internet Explorer browser does not work, according to security experts.

The "object type" vulnerability was discovered by eEye Digital Security around four months ago. A patch was released on Aug. 20. It was then re-released on Aug. 28, because under some circumstances it had caused problems for some non-default operating system installations, according to eEye. The patch appears to be due for yet another rerelease because it simply doesn't fix the vulnerability it is supposed to, eEye said.

The vulnerability in question can be exploited by crafting a malicious HTML file that, when viewed by an Internet Explorer browser, extracts and executes malicious code.

A Microsoft representative said the company was investigating the eEye report but added it has not received any reports of customers being affected by the claimed variation of the original vulnerability. The company is continuing to distribute original patch and recommends Internet Explorer users who haven't applied it, do so promptly.

Marc Maiffret, eEye's chief hacking officer, said the vulnerability is particularly critical, because it doesn't take a lot of effort to take advantage of it.

"It's pretty serious just because it's so easy to exploit...it doesn't require someone to know how to write buffer overflow exploits or anything like that," he said.

Maiffret says Microsoft should have done a better job to begin with. "How do you take four months to fix something this simple and then not fix it correctly?" he asked. "It seems like they are taking security seriously...(but) at the same time, I don't think they're really investing."

The lack of suitably skilled security engineers within Microsoft is one reason, Maiffret said, this incident--described by the researcher who discovered the flaw in the patch as a "pathetic oversight"--has occurred.

"A lot of it comes from having the right people in-house," Maiffret said. "They have some very smart guys in there, but they definitely don't have enough."

The problem with the security fix was first made public by security news and discussion site Malware.com, and Maiffret was unsure whether Microsoft was informed prior to that disclosure. "They discovered it and they're getting the information out there...I'm not sure if they gave Microsoft the information, which is usually the best way," he said.

Before the release of the patch, Maiffret's team looked over the patch and didn't see any problems. However, Maiffret said the examination was a quick "once over" and not a detailed audit. "(Our) researchers were just helping out; it's not like (Microsoft) was paying us for this," he said.

Microsoft uses external security code auditors, which in this case were not doing enough, Maiffret said.

Concerned users can disable active scripting on their browsers to mitigate the vulnerability until Microsoft updates the patch.

ZDNet Australia's Patrick Gray reported from Sydney.

Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right