By Jennifer LeClaire TechNewsWorld Part of the ECT News Network
03/24/06 10:59 AM PT
The downside of disabling scripting is the inability to access certain sites. The Windows Updates would not work if scripting is disabled, for example. That is why this is such a serious vulnerability, noted Mitchell Ashley, CTO and vice president of customer experience at StillSecure.
Is Your Website Killing Customer Confidence? Your Website's privacy policy can be a key factor in a customer's decision to do business with you, and it is vital to ensuring you don't run afoul of your online legal and regulatory responsibilities. Need more reasons? Read on.
Microsoft (Nasdaq: MSFT) has confirmed that a new vulnerability exists in its Internet Explorer Web browser. The flaw could allow an attacker to execute arbitrary code on a user's system.
The vulnerability affects IE 6.0 and Microsoft Windows XP Service Pack 2. Secunia has also confirmed the vulnerability exists in the January edition of IE7 Beta 2 Preview. Consumers who use the IE 7 Beta 2 Preview that was released on March 20 are not affected, Microsoft said.
The vulnerability is caused due to an error in the processing of the "createTextRange()" method call applied on a radio button control. A radio button is a form field that presents the user with a selection that can be chosen by clicking on a button.
Microsoft Speaks Out
"Microsoft has determined that an attacker who exploits this vulnerability would have no way to force users to visit a malicious Web site. Instead, an attacker would have to persuade them to visit the Web site, typically by getting them to click a link that takes them to the attacker's Web site," Microsoft said in its Security Advisory.
It could also be possible to display specially crafted Web content by using banner advertisements or by using other methods to deliver Web content to affected systems. In an e-mail based attack, customers would have to click a link to the malicious Web site or open an attachment that exploits the vulnerability.
An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights, Microsoft said.
Mitigating the Risk
The security world is waiting to learn whether or not Microsoft will release an out-of-cycle patch for this flaw, which is rated as extremely critical. Analysts, however, do not expect a patch until at least the first Tuesday in April. It may even be longer.
"One of the issues with this type of vulnerability is that even though the recommendations are to turn off scripting when you are dealing with text handling vulnerabilities, it touches a lot of areas of the operating system," Mitchell Ashley, CTO and vice president of customer experience at StillSecure, told TechNewsWorld.
The downside of disabling scripting is the inability to access certain sites. The Windows Updates would not work if scripting is disabled, for example. That is why this is such a serious issue, Ashley noted.
Extremely Critical
With the widespread use of radio buttons on the Web, analysts said the number of Web sites at which this vulnerability could be exploited is large. StillSecure expects to see additional exploits identified in the coming weeks.
Since disabling scripting causes other issues and is difficult for end users to do on their own, Ashley said one of the easiest ways to mitigate the risk is to use an alternate browser.
Whistleblower Says FBI E-Mail Flap Overblown March 23, 2006
"Most people who see something happening and think it's imperative to get the information to the FBI would not e-mail it," Coleen Rowley, former principal legal advisor with the bureau contended. "They would probably pick up the phone and call. "If you're working on any matter involving terrorism or counter intelligence, you can't be e-mailing any of that outside the FBI anyway," she added.
Related Stories
Microsoft Unveils Web 2.0 Strategy March 21, 2006
"Microsoft owns what we call 'the personal platform.' That's where we all live and breathe. So they have a great deal to say about where it is we are going," Enderle Group Principal Analyst Rob Enderle told TechNewsWorld. "Microsoft is using that say to carve out a space in Web 2.0."
Microsoft Throws Weight Behind People-Ready Campaign March 20, 2006
Microsoft CEO Steve Ballmer referred to several software categories that will be rolled into the People-Ready product, including unified communications and collaboration, new server technologies with the next Office, enterprise search, mobile networking, business intelligence, CRM and enhanced infrastructure.
Comparing Google, Microsoft to Netscape, IBM and Predicting Legal 'Piracy' March 20, 2006
I can picture Google employees sitting back in their chairs, frustrated that they can't fire their executives and put competent people in those jobs. I have news for those who think this way: You are killing your company.
Related News Alerts
More by Jennifer LeClaire
The Digital Car: Cool Automotive Accessories, Part 2 January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.