Most Popular Stories
- Rumor: iPad 3 will come with a quad-core A6 processor
- BlackBerry Cloud Service for Office 365 goes live
- What are you anticipating the most in Windows 8?
- Symantec drops warning against use of pcAnywhere, but questions remain
- A rundown of Windows 8 features you should know about
- Content Marketing could be supplanting the traditional corporate blog
Events
- CIO Healthcare Summit
March 11-14 — Scottsdale, AZ - Gartner CIO Leadership Forum 2012
March 25-27 — Scottsdale, AZ - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Efficiency On Demand
- Ringing in Growth - How Service Bureau-based Outsourcing is a Win-Win Approach for Communications Service Providers
- IMPROVING THE MANAGEMENT OF FEDERAL GOVERNMENT IT ASSETS THROUGH BETTER COMMUNICATION WITH THE IT INDUSTRY
- Demystifying The Android Malware
- Virtual Game Changer
IE flaw allows any file on victim's PC to be read
Security consultant Jorge Luis Alvarez Medina conducted a live demonstration that saw him exploiting (yet another) flaw in Microsoft's Internet Explorer web browser. In this instance, Medina was able to read files on the victim's local drive with impunity. And not only is the flaw said to extend across all versions of Internet Explorer, it is also "not subject to a patching fix."
In a Computerworld article, Medina said that "it doesn't appear that the IE flaw is subject to patching because it encompasses design features related to how IE and Windows Explorer handle zone elevation, HTML code and MIME types."
Workarounds involved a list of configurations such as setting "IE Network Protocol Lockdown" mode, adjusting the security on Intranet Zones to "high" and disabling Active Scripting. Honestly, I'll just as soon recommend that users switch from Internet Explorer to something with less pervasive security problems. Do you agree?
For more on this story:
- check out this article at Computerworld
Related Articles:
Chrome 4 opens the door to third-party extensions
Microsoft issues emergency patch for Internet Explorer
Firefox 3.7 should see vast speed improvements
Google Chrome is now No. 3 browser
Microsoft confirms new Internet Explorer vulnerability
Related Stories
- Lead on other browsers narrows for Internet Explorer
- Founder of Netscape to make new browser
- Firefox architect not in favor of being bundled with Windows
- Google Chrome releases 1.0; no longer in beta
- Google Apps to phase out support for older browsers
- Chrome 12 goes into beta, sheds Google Gears
- Google Chrome 11 gets bug fixes, speech input
- Run IE6 apps in IE8 with UniBrows
- Internet Explorer 9 downloaded 2.3 million times in first 24 hours
- Microsoft rolls out Internet Explorer 9 at SXSW
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




