Cross Domain Security Vulnerability in Microsoft Internet Explorer
A new IE vulnerability can permit an attacker to perform any action on the vulnerable computer that the vulnerable user can perform. The cause of this vulnerability is a flaw in the way IE handles cross-domain security checks.
December 4, 2002
Reported December 4, 2002, byMicrosoft.
VERSIONS AFFECTED
· Microsoft Internet Explorer (IE) 6.0 and 5.5
DESCRIPTION
A new IE vulnerability can permit anattacker to perform any action on the vulnerable computer that the vulnerableuser can perform. The cause of this vulnerability is a flaw in the way IEhandles cross-domain security checks.
VENDOR RESPONSE
Microsofthas released Security Bulletin MS02-068,"Cumulative Patch for Internet Explorer (Q324929),"to address this vulnerability and recommends that affected users immediatelyapply the appropriate patchmentioned in the bulletin. This cumulative patch also addresses all previouslydiscovered vulnerabilities in IE.
CREDIT
Discoveredby GreyMagic Software and ThorLarholm.
Read more about:
MicrosoftAbout the Author
You May Also Like