Microsoft IE7's zero-day hole

Microsoft warned of a new vulnerability in Internet Explorer 6 and 7 that has been targeted in attacks, and released fixes for eight holes in Windows and Office as part of Patch Tuesday.

The company issued Security Advisory 981374, which addresses a privately disclosed vulnerability. The hole could allow an attacker to take control of a machine if a user visited a malicious website, Microsoft said.

There are some features that could mitigate the effects of an attack. For instance, all supported versions of Microsoft Outlook, Microsoft Outlook Express and Windows Mail open HTML email messages in the Restricted sites zone by default, the company said.

"Protected Mode in Internet Explorer on Windows Vista and later Windows operating systems helps to limit the impact of the vulnerability as an attacker who successfully exploited this vulnerability would have very limited rights on the system," the advisory said. "By default, Internet Explorer on Windows Server 2003 and Windows Server 2008 runs in a restricted mode that is known as Enhanced Security Configuration. This mode sets the security level for the internet zone to High. This is a mitigating factor for websites that you have not added to the Internet Explorer Trusted sites zone."

The advisory also provides information on workarounds. Microsoft suggests that IE6 and IE7 users upgrade to IE8 immediately.

"For the second time in three months, Microsoft has also issued a warning about a new IE zero-day bug," said Andrew Storms, director of security operations for nCircle, referring to the IE hole that was exploited in the attacks on Google and other companies late last year and disclosed by Microsoft in January. "There's no doubt that this new bug will be fodder for the ongoing security discussion that is a key part of the browser wars."

In its Patch Tuesday preview on Thursday, Microsoft said it would issue two bulletins rated "important" on Tuesday to fix eight vulnerabilities in Windows and Microsoft Office products. Details are in the company's Security Bulletin for March.

The first bulletin for March, MS10-016, addresses a vulnerability in Windows Movie Maker that could be exploited by getting a user to open a maliciously crafted Movie Maker project file.

"Both Windows XP and Windows Vista ship with affected versions (2.1 and 6.0 respectively). Version 2.6 is also vulnerable and can be freely downloaded and installed from the web," Jerry Bryant, senior security communications manager lead at Microsoft, wrote in a blog post on the Microsoft Security Response Center. "Customers who install 2.6 on any supported platform, including Windows 7, will be offered the update."

The vulnerability also affects Microsoft Producer 2003, a free download with limited distribution. "At this time, we are not offering an update for Producer 2003," the blog post said. "While we continue to investigate Producer 2003, we recommend that customers either uninstall the application or apply an available Microsoft Fix it to disassociate the project file type from the application to add an extra layer of security."

The second bulletin, MS10-017, affects all currently supported versions of Microsoft Office Excel, as well as Office 2004 and Office 2008 for Mac, the Open XML File Format Converter for Mac, supported versions of Excel viewer and SharePoint 2007. A successful attack exploiting the hole would require a user to open a maliciously crafted file.

Meanwhile, the Malicious Software Removal Tool was updated to include Win32/Helpud, a trojan that steals log-in information for popular online games.

Microsoft also re-released MS09-033, a bulletin for a hole in Microsoft Virtual PC and Microsoft Virtual Server, to add Microsoft Virtual Server 2005 to the list of affected software.

The software giant said it is continuing to monitor threats in connection with Security Advisory 981169 related to a hole in VBScript affecting older Windows systems that Microsoft disclosed publicly on 1 March.

Although proof-of-concept code exploiting the hole has been released publicly, Microsoft said it was not aware of any active attacks. Customers using Windows 2000-, XP- and Server 2003-based systems are advised to apply the workarounds. Customers running Windows 7, Windows Server 2008, Windows Server 2008 R2 and Windows Vista are not affected.

Via CNET.com

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

The interface is nowhere near as clean and user friendly as the Rdio streaming service apps. It doesn't compete with Rdio which has very ...

16 minutes ago by Jeff12345 on Spotify finally goes live in Australia

RT @ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/0rCoszCl #infosec #hack #cybersecurity

by http://t.co/vmlLt4bh: SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the ... http://t.co/ySDRbo3l

It's official. The SKA bid has ended in a three-way tie between Australia, South Africa and New Zealand: http://t.co/Wn1niauX ^LH

Biometric bugs too dangerous for public?
http://t.co/48XQpWiY

Aussies getting ripped off by retail: Choice http://t.co/6ZQ0wuCJ via @zdnetaustralia

Thats really interesting to find this post especially in this period of my life I'm Italian, I'm owner of a website that ships worldwide...

55 minutes ago by salbini on Aussies getting ripped off by retail: Choice

Android's biggest security flaws - ZDNET - ZDNet Australia http://t.co/4j4R1x6Q

RT @Techmeme: RIP webOS: Again and for good this time (@jkendrick / ZDNet) http://t.co/RhADp6WL http://t.co/fFYGIy5R

Cybercrime golden age over in two years? http://t.co/LyqqjWYU #Cybercrime #Gescrise #Riskmanagement (via @ECCOUNCIL)

RT: ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/X0In9ijs #infosec #hack #cybersecurity

Cybercrime golden age over in two years? http://t.co/VJnt6nEo #infosec #hack #cybersecurity

NBN users opt for 100Mbps - http://t.co/C2Vs7d3t

Yes, if only he had access to FTTP instead of wishing for wireless or space optics, perhaps the comedy site would still be up and running...

1 hour ago by Beta on NBN users opt for 100Mbps

I could not resist :-)

I remember that website well, you must too, it was full of so many comedy pieces.

1 hour ago by Hubert Cumberdale on NBN users opt for 100Mbps

Bazaarvoice acquires rival PowerReviews; adds SMBs to CRM portfolio: By Andrew Nusca | May 25, 2012, 4:42am PDT ... http://t.co/WngvcsxL

MikeSkoey, what a naive collection of words. How do you know what context Paul has been working in. How do you know he implemented whats ...

2 hours ago by AnonymousCIO on 30 servers to 7: BUPA redoes virtualisation

Post 'social' improved speed to information and context http://t.co/7u9odG7N

HC, don't be so mean to Todd...

He is actually one who may not be just politically opposed ;-)

2 hours ago by Beta on NBN users opt for 100Mbps

No, Quigley is, as CEO's of all companies are, quite simply motivated for his company to be a professional and successful company, as it ...

2 hours ago by Beta on NBN users opt for 100Mbps

Forced lol. btw I tried to load your website www.nonbn.org but all I got was a "website unavailable" I really wanted to donate some mone...

2 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

http://t.co/aDIOqQ4c http://t.co/NeUOcLt5

What has the debt level got to do with what plan people chose? I'd point out that the debt wont be $50 billion but i'd be wasting my bre...

3 hours ago by mstat_z on NBN users opt for 100Mbps

Quigley is entirely politically motivated, this is headline grabbing and nothing more. The statistic should read - "of those who took up ...

3 hours ago by merarischroeder on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

"the artificial speed tiers will mean that on average speeds the country will be left well behind others and social inequality will incre...

3 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

The most insulting aspect of the ads is CommBank's expectation that we would accept a bank account with fees unless you deposit $2000/mth...

3 hours ago by gikku on Triple J's Spotify conundrum

NBN users opt for 100Mbps - Communications - News http://t.co/3A84AASP

That's right. Quigley DOES know best. So when Quigley presents a plan to the shareholders (us) and says "this is our worst case scenario...

3 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

"NBNCo predict 13% of premises passed by fibre will opt for wireless because it is cheaper." Which leaves 87% well above the 70% estimate...

4 hours ago by Beta on NBN users opt for 100Mbps

HC the critics said the NBN wouldn't make a cent (yes, yes here comes the, it's still in debt arguments - we know what you meant and so d...

4 hours ago by Beta on NBN users opt for 100Mbps

Look what you did Gwyn...LOL. Yes, but as you have been told umpteen times Mathew (whenever you sprout the same old repetitive lines abo...

4 hours ago by Beta on NBN users opt for 100Mbps

It's great that in one area NBNCo are beating the prediction on speed tiers in the Corporate Plan (page 118). Unfortunately it is the onl...

4 hours ago by mathew42 on NBN users opt for 100Mbps

10 cool iPad apps you'll wish you found sooner | 2 of 10 http://t.co/M9SXbnJS via @zite

Do you have a reference for the 40% in Willunga? The only public figures I've seen are 29% for Willunga and 26% for Kiama. It would cert...

4 hours ago by mathew42 on NBN users opt for 100Mbps

Considering that Quigley wrote the corporate plan based on a number of studies one would expect him and the plan to know best.

4 hours ago by mathew42 on NBN users opt for 100Mbps

yep don't worry, I'm sure the anti-NBN zealots will find some other ridiculous line to fill the void. I imagine it'll be "oh but these ar...

4 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

SA Health's journey to ehealth Business News ZDNet Australia: Implementing e-health services for an entire state... http://t.co/QuiOy7OQ

London to become Intel's city-living R&D testbed - ZDNet UK (blog): IT PROLondon to become Intel's city-living R... http://t.co/5qdivDa1

#Google #Australia Much ado about Google's tax http://t.co/DCMsJGyN

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

by http://t.co/vmlLt4bh: Build your own smartphone stand: Looking for a smartphone stand, but not interested in d... http://t.co/DptVvkoB

Build your own smartphone stand: Looking for a smartphone stand, but not interested in dishing out the dough? We... http://t.co/TgSeZIdM

last couple of hours to submit your application for #crmidol. Step up and take your chance! http://t.co/7vQxdbY3 #scrm #crm #value

The rural Silicon Valley http://t.co/vqV6bl5i

RT @JamesVickery: NBN users opt for 100Mbps http://t.co/atP8fi1L

Build your own smartphone stand http://t.co/IY6VxA7n

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

The rural Silicon Valley http://t.co/jhEFQwSX

JobWatch: where the ICT jobs are http://t.co/e6gQvhxz via @zdnetaustralia #ICT #recruitment

The rural Silicon Valley: What happened in Senate Estimates this week? What's the issue with tech company taxes?... http://t.co/Umoa7CHX

Sweet: "Customers are picking the top fibre plan that is available on the #NBN more than any other plan" http://t.co/yUFHdYFc

RT @CorrieB: An iPad for every child: Inevitable or impossible? http://t.co/I7uS8l9s Thx to @timbuckteeth for this; http://t.co/jxkqIRIp

Interesting tech analysis podcast re: phone cloning and Craig Thomson from zdnet http://t.co/p8jlCvvG

@zdnetaustralia Thoughtful piece to end the week on. Thanks @joshgnosis

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

3 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

3 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar