News

Vulnerability in Microsoft Internet Explorer Discovered

A vulnerability in Microsoft Internet Explorer has been discovered that could allow a malicious Web site operator, under certain circumstances, to read files on the computer of a user who visited the site.

Client-local data that is displayed in the browser can be made available to the server by using a redirect to a Javascript applet running in the same window. This bypasses cross-domain security and makes the data available to the applet, which could then send the data to a hostile server. This could allow a malicious Web site operator to read the contents of files on visiting users' computers. The vulnerability would not allow the malicious user to list the contents of the folders, create, modify or delete files, or to usurp any administrative control over the machine.

A patch is being developed by Microsoft to fix the vulnerability. Meanwhile, Microsoft recommends that Internet Explorer users add sites that they trust to the Trusted Zone in Internet Explorer, and disable Active Scripting in the Internet Zone, in order to work around the vulnerability. For more information on the vulnerability, check Microsoft's Security Bulletin FAQ.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Microsoft Starts Countdown to Dynamics GP End-of-Support

    Dynamics GP, Microsoft's venerable enterprise resource planning (ERP) solution for midsized businesses, is set to lose support in four years.

  • Image of a futuristic maze

    The 2024 Microsoft Product Roadmap

    Everything Microsoft partners and IT pros need to know about major Microsoft product milestones this year.

  • Windows Recall Preview Starts Rolling Out with Windows 11 24H2

    Microsoft on Tuesday began rolling out Windows 11 version 24H2, describing the update as a "full OS swap that contains new foundational elements required to deliver transformational Al experiences and exceptional performance."

  • An image of planes flying around a globe

    2024 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss.