Trojans target unpatched IE flaw

By Tom Espiner, ZDNet UK
06 December 2005 07:55 AM
Tags: trojan, flaw, patch, attack, exploit, tuesday, ie, sopho
Computer users have been warned that several Trojan horses that can exploit an unpatched flaw in Internet Explorer have been discovered.

Two exploits that use the recently disclosed vulnerability were reported by antivirus company Sophos on Friday. Called Clunky-B and Delf-LT, the exploits could allow malicious code to be executed remotely on a user's PC.

These Trojans could "download anything, including a 'banker Trojan' that gives up your bank details", according to a Sophos spokesperson.

Microsoft issued an advisory last week, on "the way Internet Explorer handles mismatched document object model objects". Systems running Microsoft Internet Explorer on Windows XP Service Packs 1 and 2 are vulnerable to attack. Machines running Windows 98, Windows 98 SE, Windows Me and Windows 2000 Service Pack 4 are also vulnerable to the exploits.

Microsoft is not due to issue another round of security patches until 13 December. Some security experts have suggested the company should roll out an unscheduled patch before this time to address this flaw. However, it's not clear whether the flaw will even be addressed in the next Microsoft security bulletin.

"We're working on a fix at the moment. I don't have confirmation that the patch will be available in the next round of updates, but we will include the fix in an upcoming security bulletin," said a Microsoft spokesperson.

The unpatched Internet Explorer vulnerability was first reported in May. The vulnerability was initially thought to only allow a denial-of-service attack, which would cause IE to crash.

Microsoft updated its advisory last week because "remote execution of code through this vulnerability [was found to be] possible. This is new information that's come about," said the spokesperson.

Sophos warned that the Trojans could be downloaded onto a user's computer if they visited a specially crafted Web site, and said it had found such a site. Sophos has refused to name the Web site in question, but it appears the threat to users at the moment is slight.

"It is not a hacked Web site which is in common usage -- it is unlikely that someone would visit it unprompted," said Sophos. "We don't see this in our spam traps, so it is unlikely that a wide-ranging spam campaign was used to get people to visit the dodgy site."

Sophos advised users to turn off the Active Scripting facility in Internet Explorer, as a stop-gap measure.

"Until a fix is available from Microsoft, concerned computer users should consider changing the configuration of Internet Explorer to turn off, or prompt before, allowing Active Scripting to run," said the company.

Details of the next Microsoft security bulletin will be available from 8 December.

ZDNet UK's Tom Espiner reported from London. For more coverage from ZDNet UK, click here.

Advertisement

Talkback 4 comments

    mmm Anonymous -- 06/12/05 (in reply to #120124525)

    Anyone still using ie or outlook these days is very foolish indeed!

    trace Anonymous -- 07/12/05

    why do u say that people that r still using IE or outlook are foolish - tell me what we shoud b using then.....and why?

    trace Anonymous -- 07/12/05

    why do u say that people that r still using IE or outlook are foolish - tell me what we shoud b using then.....and why?

    mmm Anonymous -- 09/12/05 (in reply to #120124604)

    Obviously you are not aware of the fact that most of the viruses,trogans,worms that are floating around the internet are targeted at windows, not to mention that ie has more holes than one of those B17's limping back from germany in WW2.Hardly a day goes by without another security threat making the news.
    Give Fire fox and Thunderbird a try, hell why not ditch windows alltogether and go Ubuntu.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured