Microsoft Admits To Zero-Day Flaw In IE 6 And 7

Microsoft has confirmed the existence of a zero-day bug in Internet Explorer 6 and 7.

Proof-of-concept attack code for the flaw was posted on 20 November to the Bugtraq mailing list. The flaw is tied to the way IE uses CSS (Cascading Style Sheets) information.

According to Microsoft, the company is looking into how to best address the matter.

“We’re aware that detailed exploit code was published on the internet for the vulnerability, but we’re currently unaware of any attacks trying to use the claimed vulnerability or of customer impact,” a Microsoft spokesperson said on 23 November. “Once we’re done investigating, we will take appropriate action to help protect customers. This may include providing a security update through the monthly release process, an out-of-cycle update or additional guidance to help customers protect themselves.”

An analysis by Vupen Security found the vulnerability is caused by a dangling pointer in the Microsoft HTML Viewer (mshtml.dll) when retrieving certain CSS/STYLE objects via the “getElementsByTagName()” method. If it is exploited successfully, attackers could crash the browser or execute arbitrary code by tricking a user into visiting a malicious web page.

As a solution, Vupen recommends users disable active scripting in the internet and local intranet security zones. If Microsoft decides to issue a patch for the vulnerability, it may come on 8 December as part of the Patch Tuesday security fixes.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Share
Published by
Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

EU Widens Investigations Into Chinese Imports, Subsidies

After the United States imposes 100 percent tariffs on certain Chinese goods, Europe widens its…

2 days ago

Reddit Deal With OpenAI Gives ChatGPT Access To Content

OpenAI strikes deal with Reddit to train its AI tech on user posts and give…

2 days ago

Microsoft Invests 4 Billion Euros In France For AI, Cloud

Global spending spree from Microsoft continues, with huge investment for new data centre to drive…

2 days ago

Toshiba Axes 4,000 Staff In Post-Delisting Restructuring Operation

Workforce blow. Newly privatised Toshiba has embarked on a 'revitalisation plan' that will entail the…

3 days ago

European Union Opens Child Safety Probe Into Meta

European Commission opens an official child safety investigation into Facebook and Instagram-owner Meta Platforms

3 days ago