Security Flaw Leaves All Microsoft Internet Explorer Users Vulnerable

CYBERSPACE — A new security hole affects all versions of Microsoft's Internet Explorer, leaving users of the leading web browser vulnerable to attack on a wide array of compromised websites.

Two online security firms have reported that hackers have broken in an unspecified number of websites and added malicious code that exploits the vulnerability in MS IE. Once installed, the virus starts stealing sensitive user data.

Online security firms Security Fix and SANS Internet Storm Center both reported on the vulnerability, which is linked to a specific file associated with MS IE. Microsoft also released an advisory, saying that the vulnerability is present in all versions of MS IE from version 5 onward.

But Washington Post tech security writer Brian Krebs noticed that some of the safety precautions recommended by Microsoft don't work quite right.

"Microsoft recommends enabling a feature called 'data execution prevention,' by clicking 'Tools,' 'Internet Options,' then 'Advanced,' and then checking the box next to that option," he said. "However, when I tried to make the changes in IE7 on Vista, I found that option grayed out. To make that change, I had to close out of IE completely, then right click on the IE icon, select 'Run as Administrator,' and then alter the setting."

Krebs also noted that Microsoft advised MS IE users to change their security setting to "high," even though such a setting renders most common websites unreadable. In addition, MS IE users can disable a specific function to prevent the attacks. The function is called "oledb32.dll." Unfortunately, Krebs also ran into trouble when trying to remove it, leading him to make a dramatic recommendation.

"I would advise Windows users to consider browsing the web with anything other than Internet Explorer, at least until Microsoft issues a patch to fix this vulnerability," he said. "It is not my intention to over-hype the situation, but as we have seen time and again, attackers are usually very quick to take advantage of flaws in IE because the program is the default browser for close to 80 percent of the planet."

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

European Commission to Assess Pornhub, XVideos, XNXX Compliance With Digital Services Act

The European Commission plans to conduct a study to determine how well adult sites Pornhub, XVideos and XNXX are addressing illegal content and other potential harms under the EU’s Digital Services Act.

German Higher Court Upholds Ban on PornHub, YouPorn

The Higher Administrative Court of Rhineland-Palatinate on Thursday upheld a “network ban” on Aylo-owned adult sites Pornhub and YouPorn for failing to comply with German age verification regulations.

Alabama Notifying Adult Sites of New Tax Set to Take Effect Sept. 1

The Alabama Department of Revenue has begun sending notices to adult site operators about a new 10% tax on their revenues, set to be enforced starting Sept. 1.

Ondato, CCBill Announce Strategic Partnership for Global High-Risk Market

Age and identity verification firm Ondato and payment processor CCBill have formed a strategic partnership to serve the global high-risk market.

Ofcom Investigates 4 More Adult Companies for OSA Compliance

U.K. media regulator Ofcom has launched investigations into whether four companies operating adult websites have implemented requisite age assurance measures under the Online Safety Act, the agency announced Thursday.

Taylor Nicole Launches New Site Through YourPaysitePartner

Creator Taylor Nicole has launched her new official website through YourPaysitePartner (YPP).

Adult Networking Platform SpicyGigs.com Launches

SpicyGigs, a new adult industry networking platform, has officially launched.

Pineapple Support to Host 'Cream Pie Challenge' Fundraiser

Pineapple Support is hosting its Cream Pie Challenge through August to raise funds for mental health services for industry performers.

Kyrgyzstan President Signs Measure Outlawing Internet Porn

President Sadyr Japarov of Kyrgyzstan on Tuesday signed into law legislation outlawing online adult content in the country.

NC Legislature Overrides Veto of Extreme Anti-Adult Industry Bill

The North Carolina state legislature on Tuesday voted to override Gov. Josh Stein’s veto of a bill imposing regulations that industry observers have warned could push adult websites and platforms to ban most creators and content.

Show More