Microsoft warns of critical IE flaws

Microsoft alerted PC users to three critical security flaws in Internet Explorer and Windows on Wednesday, as the MSBlast worm and its variants used a previous vulnerability in Windows to spread across the Net for a second week.

The software giant released a cumulative patch for Internet Explorer that fixes several vulnerabilities previously disclosed by the company, and it re-released an advisory for Microsoft's SQL Server software, warning that a flaw in that program actually affects most Windows users.

Users who don't patch their systems could leave the computers open to attack through a fake Web page or an HTML e-mail that contains the specific exploit code, said Stephen Toulouse, security program manager for Microsoft's security response centre.

"The Internet Explorer bulletin is rated as 'critical' across all platforms except Windows 2003," Toulouse said. A critical rating is the highest grade that Microsoft assigns to its alerts. The flaws were rated 'moderate'--the second-lowest grade--for Windows 2003, the latest version of the operating system.

On Wednesday, security-software maker Symantec said that MSBlast, a worm that takes advantage of a month-old vulnerability in Microsoft's OS, had infected almost 700,000 computers. A variant of the worm, MSBlast.D or Nachi, had infected more than 525,000 computers since it began to spread on Monday.

Although critical, the latest vulnerabilities are far less likely to become fodder for a worm writer because a victim would have to go to an attacker-owned Web page to be attacked.

The Internet Explorer vulnerabilities involve the fact that the software doesn't check the type of an object returned from a Web server and because a flaw exists in the browser's cross-domain security model, Microsoft stated in its advisory.

The other critical vulnerability affects all supported versions of Windows and was originally thought to be a vulnerability in Microsoft's SQL Server but is, in fact, a flaw in the omnipresent Microsoft data access component (MDAC). Windows 2003 doesn't have the vulnerable software installed by default, but a user could have downloaded the programs and so could be vulnerable.

Microsoft's Toulouse pointed out the silver lining in the latest vulnerabilities: The flaws affected Windows 2003 to a lesser degree.

"I think it is an observable bit of progress for Trustworthy Computing," Toulouse said. "The default settings of the operating system are more secure."

Advertisement

Talkback 1 comments

  1. These warnings arrive overnight via an SMS message. People interested in signing up for MS business-critical Level 1 Security Alerts should sign up here: http://members.microsoft.com/australia/technet/lounge/alerts/ Anonymous -- 21/08/03

    These warnings arrive overnight via an SMS message.

    People interested in signing up for MS business-critical Level 1 Security Alerts should sign up here:

    http://members.microsoft.com/australia/technet/lounge/alerts/


Latest Videos

ZDNet's CIO Vision Series

Department of Defence | Greg Farr, CIO (part two)

In the second part of his interview, Defence CIO Greg Farr talks about outsourcing, the skills crisis and reveals his most urgent IT priority.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Angus Kidman I'm a celebrity, don't back me up
    Celebrity comes with its perks — free alcohol, better-looking partners, lots of holiday time — and disadvantages — constant media intrusions, being forced to appear in films with Eddie Murphy for the long-term good of your career, and having to do mindless radio interviews with angry men who've been awake since 4am.
  • Array Lies, damned lies and telco stupidity
    Earlier this month, Telstra put out a press release trumpeting that it's come up with a new phone coaching service to help people who are "bamboozled" by their mobiles. Another excellent example of wrongheaded thinking from the mobile industry.
  • Array Dear carriers: More walking, less talking
    Sometimes, a well-placed and well-timed letter can make all the difference. Other times, it can make no difference at all — and even hurt your case. This week's missive by the Competitive Carriers' Coalition, I would suggest, falls into the latter category.
  • More blogs »

Tags

Back to top

Featured