News

Microsoft Warns of Bug in IE

Microsoft has released a patch that eliminates a security vulnerability in Internet Explorer (IE). The vulnerability could allow a malicious user to read, but not add, change, or delete, certain types of files on the computer of a visiting user.

When a Web server navigates a window from one domain into another, the IE security model checks the server's permissions on the new page. It is possible, however, for a Web server to open a browser window to a client-local file, then navigate the window to a page that is in the Web site's domain in such a way that the data in the client-local file is accessible to the new window. The data would only be accessible to the new window for a very brief period, but the result is that it could be possible for a malicious Web site operator to view files on the computer of a visiting user. The operator would need to know or guess the name and location of the file, and could only view file types that can be opened in a browser window.

IE 4.0, 4.01, 5, and 5.01 are all affected by the vulnerability. Patches are available at http://www.windowsupdate.microsoft.com and http://www.microsoft.com/windows/ie/security/patch5.asp. -- Isaac Slepner

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Microsoft 365 Commercial Users Getting Identity Theft Monitoring

    U.S. subscribers of Microsoft 365 Personal or Microsoft 365 Family editions are now eligible for a new Identity Theft Monitoring service, the company announced this week.

  • The 2022 Microsoft Product Roadmap

    Microsoft has a lot in the docket for 2022, including new products like SQL Server 2022, Exchange Subscription Edition and Visual Studio 2022 for Mac.

  • Report: IT Budgets To Increase Despite Slowdown in Hiring

    A newly published annual report found that 51 percent of IT departments are planning to increase their IT spending next year, even in the face of a possible recession.

  • Microsoft Bolsters 'Employee Experience' with Latest Viva Apps

    Microsoft's Viva suite is getting new apps and enhancements, according to an announcement made on Thursday.