March 21, 2006 6:11 PM PST

Another IE bug hits Microsoft

Last modified: March 23, 2006 6:55 AM PST

update Microsoft is investigating a security flaw that could let an attacker gain control over a vulnerable Windows computer, the company said Tuesday.

The flaw was reported to the company earlier this month by Jeffrey van der Stad, a 25-year-old Dutch programmer. The problem is related to the way the browser processes so-called HTA files, Microsoft said in an e-mailed statement. HTA files are associated with Web applications.

The vulnerability affects Internet Explorer 6 on Windows 98, Windows XP and Windows 2003 Server, according to van der Stad's Web site. "With this vulnerability it is possible to run an HTA file without the user's permission," he wrote.

Initially, van der Stad provided more details on his Web site, but he removed those at Microsoft's request, he wrote. A proof-of-concept exploit will be published when Microsoft issues a fix for the problem, he wrote.

Microsoft is investigating the issue, the company said. At this time, the company is not aware of any attacks attempting to use the reported vulnerability, it said.

Once it completes its inquiry, Microsoft said, it may issue a security advisory or provide a patch through its monthly release process. On his Web site, van der Stad wrote that Microsoft told him a fix is in the works.

On Wednesday, Microsoft said it is currently working on an update for IE that could be ready as soon as next month's patch day, April 11. "Microsoft will try to make the update as comprehensive as possible, but the update itself was already in development when Microsoft was made aware of these vulnerabilities so that may not be possible," a company representative said.

This is the second IE flaw within a week that Microsoft has said it is investigating and may issue a patch for. On Monday the company said it was looking into a bug that could cause the browser to crash.

Also on Wednesday, the Microsoft Security Response team on its blog said it is looking at a third IE big. The flaw has to do with the "createTextRange()" tag and could be exploited to gain control over a vulnerable PC, according to the blog posting.

"We're still investigating, but we have confirmed this vulnerability...We will address it in a security update," a Microsoft Security Response staffer wrote.

Microsoft offered a work-around, in the meantime.

"Our initial investigation has revealed that if you turn off active scripting, that will prevent the attack, as this requires script," according to a posting on Microsoft's blog.

The flaw affects fully patched versions of IE 6 and Microsoft Windows XP with Service Pack 2. The vulnerability also affects IE 7 Beta 2 Preview, according to an advisory issued by security researcher Secunia.

CNET News.com's Dawn Kawamoto contributed to this report.

See more CNET content tagged:
van, vulnerability, Microsoft Internet Explorer, Microsoft Internet Explorer 6, flaw

Add a Comment (Log in or register) 8 comments
What??
by advs89 March 21, 2006 6:18 PM PST
This is news???
Reply to this comment
same old, same old
by xtuser March 21, 2006 7:05 PM PST
basically this is what i see everyday on news.com
Reply to this comment
Think for a minute......
by OneWithTech March 21, 2006 7:59 PM PST
.....stop thinking so you can read this now.

My house is protected by ADT but I know there's a way to get
into my house from the outside. A security HOLE if you will! I
know It's there because my friend in security broke into my
house using that hole; totally bypassing the security all together.
Come to think of it that bonehead stole my Favorite Jay-Z /
Linkin Park Album.

Now I must make a decision because my buddy told the whole
state about my "HOLE" in the security at my house.

HMMMM. Mabey I'll wait till next Tuesday to fix it!

IDIOTS!

~Justin
Reply to this comment View all 2 replies
In other news, the sky is blue
by rcrusoe March 22, 2006 4:19 AM PST
and the stripped down, nothing left in it that was promised for
Longhorn, version of Vista is delayed yet again. And these stories
make headlines.

MS may not be able to deliver a product on time, or secure their
operating system, but their marketing and public relations
departments are second to none.
Reply to this comment
This story is on Auto-Repeat weekly setting
by booboo1243 March 22, 2006 7:51 AM PST
Has a week gone by since 1995 where some new Microsoft security issue is not reported on? I can't think of one.

I'm willing to bet a week's pay that CNet has a MS security hole story template, they just fill in a few blanks for names and dates and then post it on-line.
Reply to this comment View reply
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Ad trade group opposes Yahoo-Google search deal

    Association of National Advertisers announces it has sent a letter to the top antitrust chief for the U.S. Department of Justice, issuing its objections to the controversial Yahoo-Google search ad partnership.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    DemoFall preview: 10 to watch

    If you can only watch 10 pitches from DemoFall, these would be good ones.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.