| By Security News Desk | Article Rating: |
|
| March 24, 2006 02:00 AM EST | Reads: |
9,904 |
"The irresponsibility of releasing such a dangerous exploit will require systems administrators to take drastic action to protect their systems. When vulnerable home systems are added into the equation, Internet explorer users can expect a virus or worm in the very near future,” said Scott Carpenter (pictured), director of security labs at Secure Elements, when he heard that an exploit has been published for a vulnerability found in Microsoft Internet Explorer 6.x which could be used by attackers to run arbitrary code on target systems.
The flaw is due to an error when processing a "createTextRange()" call related with control objects.
“The most probable vector for this worm will be in the form of spam with malicious links that will tempt users into clicking on a link that takes them to a malicious web site," Carpenter commented. "While security researchers attempted to not disclose the actual exploit code for the vulnerability, an exploit has already been published on multiple Internet sites that can be used by anyone with even a small amount of computer skills to create seriously damaging virus or worm,” he continued.
Engineers within the Secure Elements’ Security Labs, Carpenter said, have classified the severity of this vulnerability as “10,” meaning that he vulnerability is remotely exploitable and the exploit has been released. The Secure Elements Security Lab engineers are not aware of any official patches released by Microsoft for this vulnerability. As a workaround, Secure Elements recommends disabling Active Scripting in Internet Explorer.
Published March 24, 2006 Reads 9,904
Copyright © 2006 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Security News Desk
SYS-CON's Security News desk trawls the world of security for news of software, hardware, products, and services that seems likely to be of interest to infosec professionals and summarizes them for easy assimilation by busy IT managers and staff.
![]() |
Jeff 04/01/06 12:24:18 PM EST | |||
Well....I came to this site to get the IE fix download. Where the !!!! is it. Only see news stories. How about some guidance to the free download. If ya can't find stuff on this site....I won't be back. |
||||
![]() |
IE6x 03/24/06 03:29:00 AM EST | |||
Nasty! |
||||
- An Exclusive Interview with Oracle, Cloud Expo 2010 Diamond Sponsor
- Reality Check at the Cloud Expo
- An Exclusive Interview with Adaptivity, Cloud Expo 2010 Platinum Plus Sponsor
- Virtualization Expo New York Call for Papers to Expire January 15, 2010
- Cloud Expo New York Call for Papers to Expire January 15, 2010
- Six Enterprise Megatrends to Watch in 2010
- Oracle Maps Its Cloud Computing Strategy During Cloud Expo Keynote
- Oracle Claims Victory Over EC; Says Sun Will Sell Clouds
- Free Virtual Appliance for Cloud Computing
- Seeding the Cloud: The Future of Data Management
- Current Trends in the Data Management Market
- Technology Predictions for 2010
- Cloud Expo New York Call for Papers Now Open
- An Exclusive Interview with Oracle, Cloud Expo 2010 Diamond Sponsor
- Reality Check at the Cloud Expo
- An Exclusive Interview with Adaptivity, Cloud Expo 2010 Platinum Plus Sponsor
- Cloud Expo Show Prospectus Reaches 10,000 IT Marketing Managers
- Virtualization Expo New York Call for Papers to Expire January 15, 2010
- Cloud Expo New York Call for Papers to Expire January 15, 2010
- Six Enterprise Megatrends to Watch in 2010
- Oracle Maps Its Cloud Computing Strategy During Cloud Expo Keynote
- Oracle Claims Victory Over EC; Says Sun Will Sell Clouds
- Free Virtual Appliance for Cloud Computing
- Seeding the Cloud: The Future of Data Management
- FullArmor GPAnywhere Secures Microsoft Application Virtualization Applications Through Group Policy
- Where Are RIA Technologies Headed in 2008?
- SYS-CON's Virtualization Conference & Expo: Themes & Topics
- SYS-CON's Virtualization Journal Opens Its "Readers' Choice Awards" Nominations
- Application Virtualization: Instant Migration to Vista, Fast Delivery, Secure Access, Side-by-Side Deployments
- Integration with Windows Vista, Microsoft Excel, and Microsoft Application Virtualization
- "Virtualization Is Now a Key Strategic Theme," Says Citrix CTO
- mValent Extends Automated Application Configuration Management to Virtualization Environments
- Will Microsoft Buy Citrix?
- Has the Technology Bounceback Begun?
- The Top 150 Players in Cloud Computing
- Are you Application vAvailable?

























