The Broadband Guide
SG
search advanced

Attacks Use IE to Exploit Windows MHTML Flaw

2011-03-14 09:43 by
Tags: , ,

 

New attacks are being reported using Internet Explorer to exploit a Windows vulnerability that was originally disclosed in January, but has not yet been patched. There is still no patch imminent, but there is a tool available from Microsoft to address the issue and protect your PC.

The actual flaw is with the MHTML protocol handler in Windows-not in Internet Explorer itself-and affects all versions of the Windows operating system. However, Internet Explorer is the only known attack vector for exploiting the vulnerability.

Attacks exploiting this flaw are similar to cross-site scripting attacks and enable the attacker to intercept and collect user information, spoof the content that is displayed to the browser, or interfere with the user's browsing experience in other ways. It is also possible that the attacker may be able to run malicious scripts within the context of the IE session.

At the time that the vulnerability was initially disclosed in January, it was thought that it posed little threat. Andrew Storms, director of security operations for nCircle, stated at the time, "At first glance today's advisory looks grim because it affects every supported Windows platform. However, even though the proof of concept code is public, carrying out an attack using this complicated cross site scripting-like bug will not be easy."

Read more -here-

 

  Post your review/comments
    rate:
   avg:
News Glossary of Terms FAQs Polls Cool Links SpeedGuide Teams SG Premium Services SG Gear Store
Registry Tweaks Broadband Tools Downloads/Patches Broadband Hardware SG Ports Database Security Default Passwords User Stories
Broadband Routers Wireless Firewalls / VPNs Software Hardware User Reviews
Broadband Security Editorials General User Articles Quick Reference
Broadband Forums General Discussions
Advertising Awards Link to us Server Statistics Helping SG About