Security Flaw Leaves All Microsoft Internet Explorer Users Vulnerable

CYBERSPACE — A new security hole affects all versions of Microsoft's Internet Explorer, leaving users of the leading web browser vulnerable to attack on a wide array of compromised websites.

Two online security firms have reported that hackers have broken in an unspecified number of websites and added malicious code that exploits the vulnerability in MS IE. Once installed, the virus starts stealing sensitive user data.

Online security firms Security Fix and SANS Internet Storm Center both reported on the vulnerability, which is linked to a specific file associated with MS IE. Microsoft also released an advisory, saying that the vulnerability is present in all versions of MS IE from version 5 onward.

But Washington Post tech security writer Brian Krebs noticed that some of the safety precautions recommended by Microsoft don't work quite right.

"Microsoft recommends enabling a feature called 'data execution prevention,' by clicking 'Tools,' 'Internet Options,' then 'Advanced,' and then checking the box next to that option," he said. "However, when I tried to make the changes in IE7 on Vista, I found that option grayed out. To make that change, I had to close out of IE completely, then right click on the IE icon, select 'Run as Administrator,' and then alter the setting."

Krebs also noted that Microsoft advised MS IE users to change their security setting to "high," even though such a setting renders most common websites unreadable. In addition, MS IE users can disable a specific function to prevent the attacks. The function is called "oledb32.dll." Unfortunately, Krebs also ran into trouble when trying to remove it, leading him to make a dramatic recommendation.

"I would advise Windows users to consider browsing the web with anything other than Internet Explorer, at least until Microsoft issues a patch to fix this vulnerability," he said. "It is not my intention to over-hype the situation, but as we have seen time and again, attackers are usually very quick to take advantage of flaws in IE because the program is the default browser for close to 80 percent of the planet."

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Montana District Court Denies Motion to Dismiss FSC Lawsuit in 'Major Victory'

Free Speech Coalition (FSC) scored a major victory Tuesday in its fight against Montana's age verification law, when a Montana district court denied the state's motion to dismiss the adult industry trade association's lawsuit challenging the statute.

Centrobill Launches Redesigned Merchant Portal

Payment processing service Centrobill has launched its redesigned merchant portal.

CAM4's 'XXX Factor' Talent Show Returns for 2nd Edition

CAM4’s talent show 'XXX Factor' will be back in November for a second season.

EPA United to Host Online Pre-Election Adult Industry Town Hall

Erotic Professionals & Allies United (EPA United) will host a pre-election industry town hall for sex workers and allies, Tuesday, Oct. 29 at 5 p.m. (PDT), on X.com.

'Cash-Strapped' U of Wisconsin Spent Over $130K Investigating Joe Gow

The Universities of Wisconsin reportedly spent over $130,000 investigating recently terminated communications professor and former Chancellor Joe Gow for creating and appearing in adult content.

South Dakota Lawmaker Vows to Revisit Age Verification Bill in 2025

A South Dakota state representative has vowed to reintroduce legislation in the 2025 session that would impose age verification restrictions on adult websites.

Tech Companies Propose 'Safety Codes' to Comply With Australia's Online Censor

A group of Australian trade organizations released on Monday a draft of a proposed online “safety codes” system meant to protect children from exposure to online pornography and other material categorized as “harmful content.”

#HandsOffMyPorn Campaign Doubles Its Ad Buy

The #HandsOffMyPorn campaign has doubled its ad buy in swing states ahead of next month's election.

French Court Orders Block of 4 Adult Sites Over Age Verification

The Paris Court of Appeal has ordered four adult sites blocked in France if they fail to comply with age verification requirements within 15 days.

DoggVision Relaunches Through YourPaysitePartner

DoggVision.com has relaunched through YourPaysitePartner (YPP).

Show More