Skip to main content

Microsoft warns of 'F1' pop-up flaw

posted onMarch 2, 2010
by hitbsecnews

Microsoft is looking into a new flaw that could let hackers run code if they can convince users to hit the 'F1' key in response to a pop-up window.

In a post on the Microsoft security blog, communications manager Jerry Bryant said that the flaw was made public on Friday, but that the company hadn't seen any attacks yet, and that computers running Windows 7, Vista or Sever 2008 are not affected - so XP users beware.

"The issue in question involves the use of VBScript and Windows Help files in Internet Explorer," Bryant noted. "Windows Help files are included in a long list of what we refer to as 'unsafe file types'," he explained. "These are file types that are designed to invoke automatic actions during normal use of the files. While they can be very valuable productivity tools, they can also be used by attackers to try and compromise a system."

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th