Skip to main content

Microsoft IE bug leaves users vulnerable to phishing

posted onJune 14, 2004
by hitbsecnews

The US Computer Emergency Readiness Team (US-CERT), the net security watchdog, released a security alert on Friday warning of a flaw in Microsoft's Internet Explorer which allows attackers to run programs on a user's computer. The flaw is in IE's cross-domain security model, which keeps frame content from different sources separate. This means that attackers could run programs and view files using the privileges of the user running IE.

Graham Cluley, senior technology consultant at Sophos, said on Monday that there are no reports so far of viruses or hackers exploiting this vulnerability; however, home users and businesses should be careful while "Microsoft feverishly puts the fix together".

"The flaw is not banking-specific," Cluley said, however, phishers could exploit the flaw to run a key logger, capturing Internet-banking passwords typed on the computer's keyboard. Key loggers can be installed on the computer by worms or Trojans, Cluley warned.

This is more difficult to avoid than the standard phishing attack that involves users entering their details into a fraudulent Web site, having been directed there by a spoofed email.

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th