Multiple Vulnerabilities in Microsoft Internet Explorer 6

Two vulnerabilities have been discovered in IE that can be used to bypass a security feature in Windows XP Service Pack 2 (SP2).

Ken Pfeil

November 18, 2004

1 Min Read
ITPro Today logo

Reported November 17, 2004, bycyber flash

VERSIONS AFFECTED

DESCRIPTION
Two vulnerabilities have been discovered in IE that can be used to bypass asecurity feature in Windows XP Service Pack 2 (SP2) and trick users intodownloading malicious files. These two vulnerabilities are:

Successful exploitation requires that the option "Hide extension forknown file types" is enabled (default setting). A malicious Web site can combinethese two vulnerabilites to trick a user into downloading a maliciousexecutable file masquerading as a HTML document.
 

VENDOR RESPONSE
Microsoft has notreleased a fix or bulletin that addresses this vulnerability.

CREDIT
Discovered by cyber flash.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like