Microsoft IE7's zero-day hole

Microsoft warned of a new vulnerability in Internet Explorer 6 and 7 that has been targeted in attacks, and released fixes for eight holes in Windows and Office as part of Patch Tuesday.

The company issued Security Advisory 981374, which addresses a privately disclosed vulnerability. The hole could allow an attacker to take control of a machine if a user visited a malicious website, Microsoft said.

There are some features that could mitigate the effects of an attack. For instance, all supported versions of Microsoft Outlook, Microsoft Outlook Express and Windows Mail open HTML email messages in the Restricted sites zone by default, the company said.

"Protected Mode in Internet Explorer on Windows Vista and later Windows operating systems helps to limit the impact of the vulnerability as an attacker who successfully exploited this vulnerability would have very limited rights on the system," the advisory said. "By default, Internet Explorer on Windows Server 2003 and Windows Server 2008 runs in a restricted mode that is known as Enhanced Security Configuration. This mode sets the security level for the internet zone to High. This is a mitigating factor for websites that you have not added to the Internet Explorer Trusted sites zone."

The advisory also provides information on workarounds. Microsoft suggests that IE6 and IE7 users upgrade to IE8 immediately.

"For the second time in three months, Microsoft has also issued a warning about a new IE zero-day bug," said Andrew Storms, director of security operations for nCircle, referring to the IE hole that was exploited in the attacks on Google and other companies late last year and disclosed by Microsoft in January. "There's no doubt that this new bug will be fodder for the ongoing security discussion that is a key part of the browser wars."

In its Patch Tuesday preview on Thursday, Microsoft said it would issue two bulletins rated "important" on Tuesday to fix eight vulnerabilities in Windows and Microsoft Office products. Details are in the company's Security Bulletin for March.

The first bulletin for March, MS10-016, addresses a vulnerability in Windows Movie Maker that could be exploited by getting a user to open a maliciously crafted Movie Maker project file.

"Both Windows XP and Windows Vista ship with affected versions (2.1 and 6.0 respectively). Version 2.6 is also vulnerable and can be freely downloaded and installed from the web," Jerry Bryant, senior security communications manager lead at Microsoft, wrote in a blog post on the Microsoft Security Response Center. "Customers who install 2.6 on any supported platform, including Windows 7, will be offered the update."

The vulnerability also affects Microsoft Producer 2003, a free download with limited distribution. "At this time, we are not offering an update for Producer 2003," the blog post said. "While we continue to investigate Producer 2003, we recommend that customers either uninstall the application or apply an available Microsoft Fix it to disassociate the project file type from the application to add an extra layer of security."

The second bulletin, MS10-017, affects all currently supported versions of Microsoft Office Excel, as well as Office 2004 and Office 2008 for Mac, the Open XML File Format Converter for Mac, supported versions of Excel viewer and SharePoint 2007. A successful attack exploiting the hole would require a user to open a maliciously crafted file.

Meanwhile, the Malicious Software Removal Tool was updated to include Win32/Helpud, a trojan that steals log-in information for popular online games.

Microsoft also re-released MS09-033, a bulletin for a hole in Microsoft Virtual PC and Microsoft Virtual Server, to add Microsoft Virtual Server 2005 to the list of affected software.

The software giant said it is continuing to monitor threats in connection with Security Advisory 981169 related to a hole in VBScript affecting older Windows systems that Microsoft disclosed publicly on 1 March.

Although proof-of-concept code exploiting the hole has been released publicly, Microsoft said it was not aware of any active attacks. Customers using Windows 2000-, XP- and Server 2003-based systems are advised to apply the workarounds. Customers running Windows 7, Windows Server 2008, Windows Server 2008 R2 and Windows Vista are not affected.

Via CNET.com

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Australia Live

A user from Brisbane measured 9817kbps @ Broadband Speedtest.

8 minutes ago, Click here to find out how fast your internet speed is.

RT @seesmic: Seesmic listed by @ZDNet - Top 25 Android apps: The best of the best http://ping.fm/goi9K

Dell Inspiron i14R-2265MRB http://bit.ly/caPUGs

Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too': We'll be really aggressively marketing Windows Pho... http://bit.ly/cYmvOo

News: Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too' #Geek #WebTech #News http://bit.ly/bdmUY0

Apple or Jailbreakers: Who are you gonna hang with? http://bit.ly/bA7cI0

Microsoft's Ballmer: Windows 7 slates are 'job number one': Microsoft CEO Steve Ballmer reiterated at FAM that the... http://bit.ly/cyqr98

The Facebook imperative for enterprise software http://bit.ly/dm3GtZ

Apple unveils Safari Extensions Gallery for extensions, updates for security http://bit.ly/aEpt6v

Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too' http://bit.ly/b0Z6aQ

BlackBerry encryption 'too secure': National security vs. consumer privacy - http://bit.ly/cjBUzd

BlackBerry encryption 'too secure': National security vs. consumer privacy: It's so secure, that tho... http://bit.ly/bxXN6J @sardarlawfirm

RT @ldignan: Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too' http://bit.ly/cYmvOo .. plays 2nd fiddle with "i" and phone

RT @TeamViewer: TeamViewer among 10 outstanding cross-platform apps according to ZDNet UK http://bit.ly/aNYpJ5 Thank you, Jack!

RT @seesmic: Seesmic listed by @ZDNet - Top 25 Android apps: The best of the best http://ping.fm/goi9K

RT @EverythingMS: Microsoft Internet Explorer 9 beta due in September http://bit.ly/aJoGyu

Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too' http://bit.ly/cYmvOo

Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too' http://bit.ly/cgwuDf

Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too': By Larry Dignan | July 29, 2010, 2:30pm PDT Micros... http://bit.ly/cYmvOo

Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too' http://bit.ly/bNdd9l

Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too': By Larry Dignan | July 29, 2010, 2:30pm PDT Micros... http://bit.ly/cYmvOo

Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too': By Larry Dignan | July 29, 2010, 2:30pm PDT Micros... http://bit.ly/cYmvOo

Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too': By Larry Dignan | July 29, 2010, 2:30pm PDT Micros... http://bit.ly/cYmvOo

First impressions of Apple's refreshed desktop lineup http://bit.ly/cFScu9

http://bit.ly/beopRX accounting toolbar icons News and Other Resources | ZDNet

Microsoft's Windows Phone 7 marketing pitch: 'I'm a phone too': Microsoft CEO Steve Ballmer gave analysts a glimps... http://bit.ly/cYmvOo

"Not greatly dissimilar to the public jubilation felt at the end of the second World War, Sydney-siders ..." http://bit.ly/cTvyuB #reallysad

Hilarious coverage of the iPhone 4 launch from the CNET guys. http://bit.ly/cTvyuB

What a sad way to live if the only joy in your life is to queue for a piece of defective technology sold by a vendor who accused his loya...

1 hour ago by fred9999 on iPhone 4 Australian launch: pictures

@Jetttje: outlook-alternatieven: http://www.zdnet.com.au/top-alternatives-to-microsoft-outlook-339295046.htm

RT @NASAWatch: NASA photos mooned in abandoned Maccas (LOIRP) http://bit.ly/arFI4Y

http://bit.ly/9y8rsU Multimedia Toolbar Icons - Free Software Downloads - ZDNet Australia

I am happy to know I was right about predicting Symantec's stock price and the furture trend. As I have pointed out a few times, I th...

6 hours ago by strelaoz on iPhone midnight launches across Australia

Just weirdly found out Michael Yell - Country and Regional Director for OEM, XSP and Services Business at Symantec Asia Pacific and Japan...

6 hours ago by strelaoz on iPhone midnight launches across Australia

As I have reported to Symantec Ethics about David Freer’s (VP, Symantec – Norton, APJ) misconducts (fraud, having dissented sex with ...

6 hours ago by strelaoz on iPhone midnight launches across Australia

David Freer (VP, Symantec Consumer Business Units - Norton, APJ) is a BIG LIAR! He lied to me for more than two and half years for my tru...

6 hours ago by strelaoz on iPhone midnight launches across Australia

My speed is 33 807 I'm with bigpond cable

8 hours ago by francoo on Broadband Speedtest

That is a beautiful boat,but, I'd still rather go to sea on a first flight 688 boat.Preferably the 689 if Clinton hadn't decommis...

9 hours ago by rogue689 on Get wet with submarine tech photos

For many other reasons, than just the net filter, the current has to go. Still, I wouldn't trust Abbot either. There are however chec...

10 hours ago by ian_from_oz on Conroy's filter masterstroke

RT: @zdnetaustralia: http://bit.ly/cJU6Mf We've added Virgin to our iPhone 4 pricing table comparison.. See which telco has the best deal.

The pick: five business iPad apps http://fb.me/DOid8NXt

Apple to look at iPhone 3G iOS 4 problems - Software - News http://bit.ly/cmaTAJ _ that's nice of them

Stop trying to dodge the filter issue, Conboy; it'll bite you in the **** whether you like it or not.

12 hours ago by Hyperion on Conroy pledges NBN map, same policies

@merejames http://bit.ly/9YJ6e7

Facebook va lansa un serviciu de răspunsuri la întrebările utilizatorilor http://bit.ly/aS4kLC

Survey proves #AUS e-health demand http://j.mp/ah9Iwf /via @ZDNetAustralia

A "profound cultural change" is required for a truly open government http://bit.ly/bTht86 /via @zdnetaustralia #gov2au

As one who has been as critical as any of the Sol era Telstra...as long as Telstra are leaving feasible room for profit margins for their...

14 hours ago by RS on Is Telstra the scorpion or the frog?

David, while the popular opinion, at least in the eyes of Telstra opponents, is to use every devious argument to stifle the operations of...

14 hours ago by sydneyla on Is Telstra the scorpion or the frog?

Question two: What is stopping.... "AUSTRALIANS could save up to $1.9 billion a year in travel costs, petrol and time if they spent h...

14 hours ago by Vasso Massonic on Is Telstra the scorpion or the frog?

Survey proves e-health demand: NEHTA http://itrau.com/bt9f8w via @ZDNetAustralia

David, please elaborate on Telstra's response, stating competitors could gain network access for "as Little as $2.50 a month...

15 hours ago by Vasso Massonic on Is Telstra the scorpion or the frog?

RT @zdnetaustralia: Survey by NEHTA proves there is a demand for e-health http://bit.ly/bXuT1K

RT @zdnetaustralia: Telstra cops $18.55 million fine for exchange capping http://bit.ly/9cL91V

RT @zdnetaustralia: Survey by NEHTA proves there is a demand for e-health http://bit.ly/bXuT1K #yam

A good read..RT @zdnetaustralia: Is Telstra the scorpion or the frog? http://bit.ly/cSgC31

RT @zdnetaustralia: eBay and the Trading Post online help the Australian Taxation Office catch tax cheats http://bit.ly/dBDXRz

im gonna get it, if i dont like it i flush it down the toilet i dont care im rich, yeah you negative people should get a life

15 hours ago by booostking on Date set for Aussie iPhone 4 release

Umm, what is wrong with these two, chronological sentences from above, from Paul Fletcher? "We are deeply concerned that the new pro...

15 hours ago by RS on Lundy vs. Ludlam, Fletcher: election debate

RT @zdnetaustralia Tesltra tweaks its data plans for all smartphones (not just the iPhone 4) http://bit.ly/bxO0G2

RT @zdnetaustralia: Is Telstra the scorpion or the frog? http://bit.ly/cSgC31

Is Telstra the scorpion or the frog? http://bit.ly/cSgC31

@mibus http://www.zdnet.com.au/commbank-dives-into-580m-banking-it-revamp-339288467.htm

The tech keeping Plastiki afloat: photos: ZDNet Australia brings you the tech below deck on the epic Plastiki voyage. http://bit.ly/aTj1QU

http://bit.ly/cJU6Mf We've added virgin to our iPhone 4 pricing table comparison.. See which telco has the best deal.

Telstra boosts smartphone data: In a few hours, Apple's hyped iPhone 4 handset will launch in Australia. But Telst... http://bit.ly/a3E7wi

This story has been liked 5 times in the last 24 hours!

1) Apple iPhone 4 16GB31 plans 16%
2) Apple iPhone 4 32GB32 plans 15%
3) Samsung Galaxy S19 plans 11%
4) Apple iPhone 3GS 32GB16 plans 1%
5) Apple iPhone 3GS 16GB13 plans 8%

Mobile Phones | Broadband

CBS - ZDNET Australia Partner Services