• On GameSpot: Wii Fit tells 10-year-old she's fat

November 30, 2005 12:16 PM PST

Trojan horse rides on unpatched IE flaw

Attackers are taking advantage of an unpatched vulnerability in Internet Explorer to target users of the ubiquitous Web browser, Microsoft warned late Tuesday.

Malicious software that exploits the security flaw to download a Trojan horse to vulnerable computers has been found on the Internet, according to Microsoft. Detection and removal capabilities for the "TrojanDownloader:Win32/Delf.DH" have been added to Microsoft's recently launched online security-scanning tool.

"Customers can visit Windows Live Safety Center and are encouraged to use the Complete Scan option to check for and remove this malicious software and future variants," Microsoft said in its updated security advisory on the issue.

The security bug, exploited by the Trojan downloader, was originally reported in May. The bug was thought to only allow for a denial-of-service attack, which would cause IE to close. However, experts last week raised an alarm on the issue because it was discovered that it could be used to remotely run code on a vulnerable computer.

Microsoft has yet to provide a fix for the vulnerability, but is working on a patch, according to the security advisory. Security-monitoring company Secunia deems the problem "extremely critical," its rarely given highest rating.

The vulnerability puts computers running Windows 98, Windows Millennium Edition, Windows 2000 and Windows XP at risk. An attacker could gain complete control of vulnerable systems by hosting malicious code on a Web site. Once an IE user visits the site, the malicious program would run without any user interaction.

Microsoft offers several workarounds to deflect attacks. These include changing IE settings to disable active scripting or prompt the user before running such scripts.

See more CNET content tagged:
trojan horse, Microsoft Windows ME, Microsoft Internet Explorer, malicious software, vulnerability

Add a Comment (Log in or register) 19 comments
Considering
by Hobo453567 November 30, 2005 1:00 PM PST
Considering the fact that everyone jumps on Sony when they screw up I am surprised there were no comments here. MS has never released a finished product and yet it seems as though people have accepted that and are okay with it. Why do people jump all over anyone but MS when they screw up? Is it because MS usually tells people they screwed up? I am just tired of people immediately jumping on other companies but being "okay" with what MS does.
Reply to this comment View all 6 replies
Owned.
by Techie2010 December 1, 2005 8:54 AM PST
More of a reason to use Firefox. Microsoft needs to get its ass in gear or they're gonna fall behind.
Reply to this comment View reply
Hey!
by Eskiegirl302 December 1, 2005 10:51 PM PST
I just switched to FireFox a couple days ago. It has tons of extensions, and I am still reading the site. So far I like it ok. Used IE for years. Never tried Opera, for the reason he said. Not gonna pay for it. I got my google bar that is what I most care about, and the dude who invented FireFox just went to work at google. That's cool, cause soon Google is coming out with its own antivirus. I love it. Go guys Go!
Reply to this comment
Well then-- ACK
by murophelia December 2, 2005 6:02 AM PST
So my computer has been compromised and completely hijacked since 12 November. And it sucks. Can anyone fix it? No.

We also use a MAC.
I dont think I am going back to the Gates of Hell.
Reply to this comment View reply
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right