<tt id="6hsgl"><pre id="6hsgl"><pre id="6hsgl"></pre></pre></tt>
          <nav id="6hsgl"><th id="6hsgl"></th></nav>
          国产免费网站看v片元遮挡,一亚洲一区二区中文字幕,波多野结衣一区二区免费视频,天天色综网,久久综合给合久久狠狠狠,男人的天堂av一二三区,午夜福利看片在线观看,亚洲中文字幕在线无码一区二区
            Home>News Center>World
                   
           

          'Extremely critical' flaw threatens IE users
          (Agencies)
          Updated: 2005-01-12 08:04

          Security experts are warning of a new and highly critical security flaw in Microsoft Internet Explorer, when running under Windows XP SP2.

          Simply visiting a malicious Web site could leave a user's computer vulnerable to malicious code.

          The basic flaw has been known about for two months, but security experts originally thought it would be difficult to exploit. However, after further study, security firm Secunia now says the bug represents a greater danger than previously believed.

          Secunia now rates the vulnerability as "extremely critical."

          Three Problems

          In an alert posted on its Web site, Secunia lists three problems in IE that, in combination, create the vulnerability:

          "Insufficient validation of drag and drop events from the Internet zone to local resources for valid images or media files with embedded HTML code;

          "A security site/zone restriction error, where an embedded HTML Help control on e.g. a malicious web site references a specially crafted index (.hhk) file, can execute local HTML documents or inject arbitrary script code in context of a previous loaded document using a malicious javascript URI handler;

          "A security site/zone restriction error in the handling of the Related Topics command in an embedded HTML Help control can be exploited by e.g. a malicious website to execute arbitrary script code in the context of arbitrary sites or zones."

          The exploit bypasses a key SP2 security feature, Zone Lock Down, which is designed to prevent an attacker from remotely executing script on a local system.

          Safety Measures

          The vulnerability was identified initially by security group Greyhats, which warned of the bug late last month.

          Microsoft is recommending that users turn off the "Drag and drop or copy and paste files" option in Internet Explorer and set security levels to high for the Internet zone.

          Security experts note that the problem does not affect other browsers.

          Secunia has constructed a test, available on the firm's Web site, that users can run to determine whether their systems are affected by this issue.

          Microsoft releases Windows security fixes

          Microsoft Corp. released two security fixes Tuesday that carry its most severe threat rating, including one that applies even to computers that have downloaded the company's massive security update for the Windows XP operating system.

          Both flaws affect versions of the company's dominant operating system going back to Windows 98, and both could allow an attacker to take control of another person's computer.

          One of the flaws also leaves vulnerable users who have downloaded Service Pack 2, a major security upgrade for Windows XP that was released last summer. The security fix came after a series of crippling attacks on Microsoft's technology, which have wreaked havoc on both businesses and computer users.

          Stephen Toulouse, a security program manager at Redmond-based Microsoft, said the company never expected SP 2 to solve all of its security problems.

          "We knew we were going to be providing updates for SP2," he said. "The goal was always around reducing the number of critical updates."

          The flaw that affects SP2 takes advantage of a problem with Internet Explorer that could allow an attacker to gain control of a computer if a user was persuaded to visit a malicious Web site.

          The other flaw could be exploited if a user employs a specially formulated cursor or icon that secretly allowed an attacker to gain control of another person's computer.

          Microsoft also released a third security fix Tuesday with a lesser rating of "important." That vulnerability, which also could allow another person to gain control of a user's computer, affects machines running Windows XP and Windows Server 2003.

          The new security fixes, released as part of Microsoft's regular monthly security updates, come a week after Microsoft said it would begin offering a free program to remove the most dangerous infections from computers. Users who have chosen to automatically receive Microsoft security fixes would begin to receive that removal tool Tuesday, Toulouse said.

          Last week the company also began offering a free program to remove spyware. Spyware can monitor computer users' activities, send annoying pop-up ads and slow computer performance.

          Microsoft also has confirmed plans to sell its own antivirus software, which would compete against programs from McAfee, Symantec and others.



           
            Today's Top News     Top World News
           

          Nation jumps to be world third largest trader

           

             
           

          Hu offers systematic cure to corruption

           

             
           

          Cross-Straits charter flight talks proposed

           

             
           

          Draft law aims to hold back monopolies

           

             
           

          Wintry Beijing tackles heating shortfalls

           

             
           

          'Extremely critical' flaw threatens IE users

           

             
            Allawi admits some areas unsafe to vote
             
            Bush picks ex-prosecutor for homeland post
             
            Sharon phones Abbas in highest contact in years
             
            'Extremely critical' flaw threatens IE users
             
            New case of mad cow confirmed in Canada
             
            Death toll in Australian bushfires rises to 10
             
           
            Go to Another Section  
           
           
            Story Tools  
             
            News Talk  
            Are the Republicans exploiting the memory of 9/11?  
          Advertisement
                   
          主站蜘蛛池模板: 亚洲中文字幕无码爆乳APP| 亚洲综合网国产精品一区| 亚洲综合精品中文字幕| 毛多水多高潮高清视频| 成人看的污污超级黄网站免费| 亚洲自偷自偷偷色无码中文 | 无码人妻人妻经典| 久久无码中文字幕免费影院| 中文人妻av高清一区二区| 亚洲乱码一卡二卡卡3卡4卡| 日韩黄色av一区二区三区| 国产一区二区三区禁18| 亚洲中文无码永久免费| 人妻丰满熟妇AV无码区乱| 无码人妻丰满熟妇啪啪| 国产中文字幕精品在线| P尤物久久99国产综合精品| 亚洲黄色第一页在线观看| 日本福利视频免费久久久| 久久精品国产亚洲成人av| 久久亚洲精品中文字幕波多野结衣 | 久久中精品中文字幕入口| 成人一区二区三区在线午夜| 日本一高清二区视频久二区| 男人av无码天堂| 日韩极品视频在线观看免费| 国产亚洲精品久久久久秋霞| 国产午夜福利小视频在线| 欧美性猛交xxxx富婆| 精品国产精品国产偷麻豆| 无码国内精品人妻少妇| 亚洲综合成人av在线| 亚洲一区二区视频在线观看| 精品 无码 国产观看| 377P欧洲日本亚洲大胆 | 在线视频中文字幕二区| 麻豆蜜桃av蜜臀av色欲av | 午夜A理论片在线播放| 日本熟妇浓毛| 精品一区二区三区在线播放视频| 永久免费无码av在线网站|