Breaking News

LIAN LI Launches Multi-Directional Vertical GPU Mounting Bracket with PCIe 5.0 Riser Cable Samsung announces Galaxy Tab S10 Lite Nikon releases the NIKKOR Z 24-70mm f/2.8 S II CORSAIR ONE a600 Brings Improved Cooling and Adaptive Performance in a Compact Design Speedlink setting the tone in the gaming zone

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Microsoft Warns Of New IE Bug

Microsoft Warns Of New IE Bug

Enterprise & IT Jan 29,2011 0

Microsoft on Friday warned Windows users of a new vulnerability that attackers could exploit to steal information and dupe people into installing malware. The company is investigating public reports of a vulnerability in all supported editions of Microsoft Windows. The vulnerability could allow an attacker to cause a victim to run malicious scripts when visiting various Web sites, resulting in information disclosure. This impact is similar to server-side cross-site scripting (XSS) vulnerabilities, Microsoft said.

MHTML is a Web page protocol that combines resources of several different formats into a single file. Only Microsoft's IE and Opera Software's Opera support MHTML natively, while Google's Chrome and Apple's Safari do not, and Firefox requires an add-on to read and write MHTML files.

The company is aware of published information and proof-of-concept code that attempts to exploit this vulnerability but it has not yet seen any indications of active exploitation of the vulnerability.

"The vulnerability exists due to the way MHTML (MIME Encapsulation of Aggregate HTML) protocol interprets MIME-formatted requests for content blocks within a document. It is possible under certain conditions for this vulnerability to allow an attacker to inject a client-side script in the response of a Web request run in the context of the victim's Internet Explorer. The script could spoof content, disclose information, or take any action that the user could take on the affected Web site on behalf of the targeted user," Microsoft said.

The impact of an attack on the vulnerability would be similar to that of server-side cross-site-scripting (XSS) vulnerabilities. For instance, an attacker could construct an HTML link designed to trigger a malicious script and somehow convince the targeted user to click it. When the user clicked that link, the malicious script would run on the user's computer for the rest of the current Internet Explorer session. Such a script might collect user information (eg., email), spoof content displayed in the browser, or otherwise interfere with the user's experience.

The workaround: Microsoft is recommending users apply locks down the MHTML protocol by running a "Fixit" tool it's made available.

Microsoft is currently working on a security update to address this vulnerability.

Tags: Microsoftinternet explorer
Previous Post
Sony Unveils Slate of New Games for the PlayStation Network
Next Post
Intel SSD 510 Series With SATA III Interface Available For Pre-order

Related Posts

  • Snapdragon X Series is the Exclusive Platform to Power the Next Generation of Windows PCs with Copilot+ Today

  • Activision Blizzard King to Team Xbox

  • NVIDIA Studio Lineup Adds RTX-Powered Microsoft Surface Laptop Studio 2

  • Samsung and Microsoft Unveil First On-Device Attestation Solution for Enterprise

  • Introducing Xbox Game Pass Core, Coming This September

  • Announcing the next wave of AI innovation with Microsoft Bing and Edge

  • Microsoft Announces Security Copilot AI

  • Microsoft breaks new ground in healthcare with the next evolution of AI

Latest News

LIAN LI Launches Multi-Directional Vertical GPU Mounting Bracket with PCIe 5.0 Riser Cable
Enterprise & IT

LIAN LI Launches Multi-Directional Vertical GPU Mounting Bracket with PCIe 5.0 Riser Cable

Samsung announces Galaxy Tab S10 Lite
Consumer Electronics

Samsung announces Galaxy Tab S10 Lite

Nikon releases the NIKKOR Z 24-70mm f/2.8 S II
Cameras

Nikon releases the NIKKOR Z 24-70mm f/2.8 S II

CORSAIR ONE a600 Brings Improved Cooling and Adaptive Performance in a Compact Design
Cooling Systems

CORSAIR ONE a600 Brings Improved Cooling and Adaptive Performance in a Compact Design

Speedlink setting the tone in the gaming zone
PC components

Speedlink setting the tone in the gaming zone

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Terramaster F8-SSD

Terramaster F8-SSD

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Pure Base 501

be quiet! Pure Base 501

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed