Most Popular Stories
Events
- Register for The Security Standard 2010
September 13 - 14 — New York, NY - Gov 2.0 Summit
September 7 - 8 — Washington, DC - SharePoint Technology Conference
October 20 - 22 — Boston, MA - Northwestern University Master of Science in Information Systems (MSIS)
Sponsored Links
HOT TOPICS >> Q2 Earnings Roundup | Cloud Computing | Tablets | Security Vulnerabilities and Exploits
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Cloud Computing: How To Make Your Own Silver Lining
- The Shortcut Guide to Secure, Managed File Transfer
- Enterprise Digital Assistant Leverage in the Emerging Mobile Enterprise
- Reporting 2.0 – The next evolutionary step in web based business reporting
- 5 Must Haves in your Information Management Strategy
We never sell or give away your contact information. Our reader's trust comes first.
Microsoft confirms new Internet Explorer vulnerability
Microsoft has confirmed the presence of a previously undiscovered flaw that affects Internet Explorer 6 and Internet Explorer 7. A Microsoft spokesperson noted, "We're aware that detailed exploit code was published on the Internet for the vulnerability, but we're currently unaware of any attacks trying to use the claimed vulnerability or of customer impact."
In this case, the vulnerability is related to how Internet Explorer deals with cascading style sheets, or CSS. CSS is used to describe the layout of a web page, and is a crucial element of modern web site design. For now, security vendor Symantec says that the attack code is "a bit buggy and unreliable," though you can be sure this will not stay that way for long.
Security analysis by vulnerability management firm VUPEN has determined that disabling active scripting in the Internet and Local intranet security zones could help to temporarily mitigate this problem. Visiting only "trusted websites" is also recommended until Microsoft issues a patch that fixes this vulnerability.
Of course, older versions of Internet Explorer, especially IE6, have been plagued by the repeated discovery of security vulnerabilities. Rather than trying to limit visits to "trusted websites"--and how is someone supposed to do that anyway--perhaps switching to newer versions of IE, or even ditching it altogether in favor of browsers such as Firefox and Opera, might be a wise move.
For more on this story:
- check out this eWeek article
- check out this Washington Post article
Related Articles:
Lead on other browsers narrows for Internet Explorer
Microsoft: Internet Explorer 9 will be faster
Report: Internet Explorer 8 effective in blocking phishing
USDA unit limits browsers to Internet Explorer
Related Stories
- Microsoft releases 11 patches, 6 critical
- Hackers may target your printer
- Browser flaw hits IE and Firefox
- New flaw impacts Outlook, not IE7
- IE flaw could prove troublesome
- Phishers using BBC news to infect PCs
- Microsoft release security advisory about remote DLL flaw
- New Windows kernel bug surfaces days before Microsoft's largest Patch Tuesday
- New security holes found in Internet Explorer
- Serious flaw discovered in Microsoft IIS
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2010 FierceMarkets. All rights reserved. |
![]() |







