Breaking News

ADATA Launches T7 and T5 Enterprise SSD Series ASUSTOR Embraces the AI Boom at COMPUTEX 2025 Sony announces DualSense wireless controller for Death Stranding 2 ASUS Celebrates DOOM The Dark Ages Collaboration with Global Bundle LG Display to Showcase World's Best Solutions for Future Mobility at SID Display Week 2025

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Microsoft Warns Of New IE Bug

Microsoft Warns Of New IE Bug

Enterprise & IT Jan 29,2011 0

Microsoft on Friday warned Windows users of a new vulnerability that attackers could exploit to steal information and dupe people into installing malware. The company is investigating public reports of a vulnerability in all supported editions of Microsoft Windows. The vulnerability could allow an attacker to cause a victim to run malicious scripts when visiting various Web sites, resulting in information disclosure. This impact is similar to server-side cross-site scripting (XSS) vulnerabilities, Microsoft said.

MHTML is a Web page protocol that combines resources of several different formats into a single file. Only Microsoft's IE and Opera Software's Opera support MHTML natively, while Google's Chrome and Apple's Safari do not, and Firefox requires an add-on to read and write MHTML files.

The company is aware of published information and proof-of-concept code that attempts to exploit this vulnerability but it has not yet seen any indications of active exploitation of the vulnerability.

"The vulnerability exists due to the way MHTML (MIME Encapsulation of Aggregate HTML) protocol interprets MIME-formatted requests for content blocks within a document. It is possible under certain conditions for this vulnerability to allow an attacker to inject a client-side script in the response of a Web request run in the context of the victim's Internet Explorer. The script could spoof content, disclose information, or take any action that the user could take on the affected Web site on behalf of the targeted user," Microsoft said.

The impact of an attack on the vulnerability would be similar to that of server-side cross-site-scripting (XSS) vulnerabilities. For instance, an attacker could construct an HTML link designed to trigger a malicious script and somehow convince the targeted user to click it. When the user clicked that link, the malicious script would run on the user's computer for the rest of the current Internet Explorer session. Such a script might collect user information (eg., email), spoof content displayed in the browser, or otherwise interfere with the user's experience.

The workaround: Microsoft is recommending users apply locks down the MHTML protocol by running a "Fixit" tool it's made available.

Microsoft is currently working on a security update to address this vulnerability.

Tags: Microsoftinternet explorer
Previous Post
Sony Unveils Slate of New Games for the PlayStation Network
Next Post
Intel SSD 510 Series With SATA III Interface Available For Pre-order

Related Posts

  • Snapdragon X Series is the Exclusive Platform to Power the Next Generation of Windows PCs with Copilot+ Today

  • Activision Blizzard King to Team Xbox

  • NVIDIA Studio Lineup Adds RTX-Powered Microsoft Surface Laptop Studio 2

  • Samsung and Microsoft Unveil First On-Device Attestation Solution for Enterprise

  • Introducing Xbox Game Pass Core, Coming This September

  • Announcing the next wave of AI innovation with Microsoft Bing and Edge

  • Microsoft Announces Security Copilot AI

  • Microsoft breaks new ground in healthcare with the next evolution of AI

Latest News

ADATA Launches T7 and T5 Enterprise SSD Series
Enterprise & IT

ADATA Launches T7 and T5 Enterprise SSD Series

ASUSTOR Embraces the AI Boom at COMPUTEX 2025
Enterprise & IT

ASUSTOR Embraces the AI Boom at COMPUTEX 2025

Sony announces DualSense wireless controller for Death Stranding 2
Gaming

Sony announces DualSense wireless controller for Death Stranding 2

ASUS Celebrates DOOM The Dark Ages Collaboration with Global Bundle
Gaming

ASUS Celebrates DOOM The Dark Ages Collaboration with Global Bundle

LG Display to Showcase World's Best Solutions for Future Mobility at SID Display Week 2025
Enterprise & IT

LG Display to Showcase World's Best Solutions for Future Mobility at SID Display Week 2025

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Rock 5

be quiet! Dark Rock 5

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

Arctic Liquid Freezer III 420 - 360

Arctic Liquid Freezer III 420 - 360

Crucial Pro OC 32GB DDR5-6000 CL36 White

Crucial Pro OC 32GB DDR5-6000 CL36 White

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed