Skip to main content

Another unpatched IE bug detailed

posted onApril 29, 2006
by hitbsecnews

A security researcher has publicly disclosed a security flaw in Internet Explorer, the second unpatched vulnerability in the Microsoft browser to be disclosed publicly within a week.

The flaw lies in the way IE, the world's most used Web browser, handles certain dialogs, bug hunter Matthew Murphy wrote in an advisory sent to the Full Disclosure mailing list earlier this week.

"As a result, it may be possible for a malicious Web site to install software on a visiting system or take other actions that may compromise the privacy or the security of the visitor," he wrote. Microsoft was informed in October last year, Murphy wrote.

Microsoft acknowledges the issue, but said it does not plan to issue a security update for it. "The vulnerability cannot be used to execute code on a user's system without multiple user actions that are uncommon in typical Web browsing scenarios," a company representative said in an e-mailed statement.

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th