Microsoft Investigating MHTML Vulnerability in IE
Microsoft released Security Advisory 2501696 in response a scripting vulnerability in Internet Explorer that affects all versions of Windows.
The security hazard is found in the MIME Encapsulation of Aggregate HTML (MHTML) protocol handler. The attach mechanism is similar to a server-side cross-site-scripting (XSS) exploit, in which a malicious script could run on a user's computer after clicking on a link. While this vulnerability could be exploited by hackers, the chances of an attack are slim, according to some software security analysts.
"At first glance today's advisory looks grim because it affects every supported Windows platform," wrote Andrew Storms, director of information and technology at software security firm nCircle, in a released statement. "However, even though the proof of concept code is public, carrying out an attack using this complicated cross site scripting-like bug will not be easy."