Security Flaw Leaves All Microsoft Internet Explorer Users Vulnerable

CYBERSPACE — A new security hole affects all versions of Microsoft's Internet Explorer, leaving users of the leading web browser vulnerable to attack on a wide array of compromised websites.

Two online security firms have reported that hackers have broken in an unspecified number of websites and added malicious code that exploits the vulnerability in MS IE. Once installed, the virus starts stealing sensitive user data.

Online security firms Security Fix and SANS Internet Storm Center both reported on the vulnerability, which is linked to a specific file associated with MS IE. Microsoft also released an advisory, saying that the vulnerability is present in all versions of MS IE from version 5 onward.

But Washington Post tech security writer Brian Krebs noticed that some of the safety precautions recommended by Microsoft don't work quite right.

"Microsoft recommends enabling a feature called 'data execution prevention,' by clicking 'Tools,' 'Internet Options,' then 'Advanced,' and then checking the box next to that option," he said. "However, when I tried to make the changes in IE7 on Vista, I found that option grayed out. To make that change, I had to close out of IE completely, then right click on the IE icon, select 'Run as Administrator,' and then alter the setting."

Krebs also noted that Microsoft advised MS IE users to change their security setting to "high," even though such a setting renders most common websites unreadable. In addition, MS IE users can disable a specific function to prevent the attacks. The function is called "oledb32.dll." Unfortunately, Krebs also ran into trouble when trying to remove it, leading him to make a dramatic recommendation.

"I would advise Windows users to consider browsing the web with anything other than Internet Explorer, at least until Microsoft issues a patch to fix this vulnerability," he said. "It is not my intention to over-hype the situation, but as we have seen time and again, attackers are usually very quick to take advantage of flaws in IE because the program is the default browser for close to 80 percent of the planet."

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Woodhull Urges the Supreme Court to Find Texas AV Law Unconstitutional

The Woodhull Freedom Foundation and the Electronic Frontier Foundation submitted a brief to the United States Supreme Court on Thursday, urging the justices to rule against Texas’ age verification law.

AEBN Publishes Popular Searches for March and April

AEBN has released the top search terms for the months of  March and April from its straight and gay theaters in all 50 states and the District of Columbia.

2024 XBIZ Creator Awards Winners Announced

Winners of the 2024 XBIZ Creator Awards were revealed Wednesday evening during a live ceremony at E11EVEN Nightclub in Miami, Florida. The event, presented by Fansly, was hosted by Siri Dahl and Little Puck.

'90s Japanese Performer Sues to Remove Titles from Streaming Site

Former Japanese performer Miyuki Ariga is suing the Fanza adult streaming site at the Tokyo District Court to remove four titles in which she appeared in 1994.

Free Speech Coalition Asks Court to Block Montana AV Law

The Free Speech Coalition (FSC) has asked the US District Court of Montana to block the state's new age verification law.

Segpay Launches Virtual 'Segcard' Creator Payout Solution

Segpay has updated its Segcard creator payout option by offering a new, virtual version.

Leading Conservative Think Tank Slams 5th Circuit for Upholding Texas Age Verification Law

Leading conservative think tank the American Enterprise Institute has published an opinion piece penned by one of its senior fellows criticizing the 5th Circuit endorsement of Texas’ controversial age verification law.

OpenAI Shuts Down AI-Generated Porn Rumors

A spokesperson for OpenAI, the company behind ChatGPT, has shut down online chatter about how a rumored relaxation of the company’s stance against AI-generated NSFW content may result in a lifting of its porn ban.

Former Trump Staffer, Project 2025 Advisor John McEntee Predicts a Total Porn Ban

John McEntee, senior advisor to the Heritage Foundation’s Project 2025 and a former key figure in the Trump administration, is predicting an eventual full ban on pornography, claiming that once it is enacted, “this country will flourish.”

Vendo Launches 'Pay by Bank' Service

Vendo has launched its new Pay by Bank checkout system.

Show More