Cross Domain Security Vulnerability in Microsoft Internet Explorer

A new IE vulnerability can permit an attacker to perform any action on the vulnerable computer that the vulnerable user can perform. The cause of this vulnerability is a flaw in the way IE handles cross-domain security checks.

Ken Pfeil

December 4, 2002

1 Min Read
ITPro Today logo

Reported December 4, 2002, byMicrosoft.

VERSIONS AFFECTED

 

·        Microsoft Internet Explorer (IE) 6.0 and 5.5

 

 

DESCRIPTION

 

A new IE vulnerability can permit anattacker to perform any action on the vulnerable computer that the vulnerableuser can perform. The cause of this vulnerability is a flaw in the way IEhandles cross-domain security checks.

 

VENDOR RESPONSE

 

Microsofthas released Security Bulletin MS02-068,"Cumulative Patch for Internet Explorer (Q324929),"to address this vulnerability and recommends that affected users immediatelyapply the appropriate patchmentioned in the bulletin. This cumulative patch also addresses all previouslydiscovered vulnerabilities in IE.

 

CREDIT          

Discoveredby GreyMagic Software and ThorLarholm.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like