It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Microsoft warns of IE flaw, turns PC into public file server Microsoft warns of IE flaw, turns PC into public file server
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Microsoft warns of IE flaw, turns PC into public file server
Reply
 
Thread Tools
Old 5th February 2010, 09:48   #1
Madshrimp
 
jmke's Avatar
 
Join Date: May 2002
Location: 7090/Belgium
Posts: 79,021
jmke has disabled reputation
Default Microsoft warns of IE flaw, turns PC into public file server

Microsoft has issued Security Advisory (980088) to address a publicly disclosed vulnerability in Internet Explorer that may allow information disclosure for Windows XP users or for users who have disabled Internet Explorer Protected Mode. The advisory explains that content can be forced to render incorrectly from local files in such a way that information can be exposed to malicious websites.

The vulnerability was discussed in depth at this week's Black Hat DC conference by Jorge Luis Alvarez Medina, a security consultant with Core Security Technologies who revealed the issue a day after Microsoft released an out-of-band security bulletin for the browser. Here's the official description of the briefing: "In this presentation we will show how an attacker can read every file of your filesystem if you are using Internet Explorer. This attack leverages different design features of Internet Explorer entailing security risks that, while low if considered isolated, lead to interesting attack vectors when combined altogether. We will also disclose and demonstrate proof of concept code developed for the scenarios proposed."

http://arstechnica.com/microsoft/new...campai gn=rss
__________________
jmke is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft warns of TLS/SSL flaw in Windows jmke WebNews 0 10th February 2010 13:28
Microsoft patching "Google hack" flaw in IE tomorrow jmke WebNews 1 21st January 2010 09:56
Microsoft Patch Tuesday: 5 Criticals, 2 Important, 1 Moderate Patch jmke WebNews 0 14th April 2009 18:47
Microsoft plans new entry-level Windows server jmke WebNews 0 26th February 2009 16:19
Microsoft Security Bulletin Summary for September 2008 jmke WebNews 0 9th September 2008 19:20
Microsoft Security Bulletin Summary for August 2007 jmke WebNews 0 14th August 2007 22:21
Microsoft Security Bulletin Summary for February 2007 jmke WebNews 0 14th February 2007 00:25
Microsoft Security Bulletin Summary for June 2006 jmke WebNews 0 14th June 2006 20:51
List of fixes included in Windows XP Service Pack 2 jmke WebNews 1 17th August 2004 15:03
HP and Microsoft Expand Security Solutions Portfolio Sidney WebNews 0 25th May 2004 06:28

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 21:33.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO