Government Releases Details of IE Vulnerability

US-CERT, the Department of Homeland Security's Computer Emergency Readiness Team, has released details of a security flaw in Microsoft's Internet Explorer browser. According to the report, IE does not properly restrict access to a document's frames. By tricking a user into viewing a specially crafted HTML document, a hacker could then access non-domain-specific elements (i.e., an onmousedown event) from a Web page that exists in another domain. Since the victim does not realize that they are interacting with a different domain at this point, the attacker can then exploit the flaw in several malicious ways including capturing keystrokes.
Internet Explorer 6, 7, and even IE8 Beta 1 are at risk here. The only workaround available at the moment is to disable Active Scripting in the Internet Zone.
(Photo © altvisor - #628229/stockxpert)

Comments
No comments yet. Leave a Comment