Welcome to P2PNET.net - The original daily p2p and digital news site. Always First!
Register | Login
RIAA News
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
TV
Open Source
Mobiles
Advertising
Product News
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Search: 
Search
 
Web P2PNET   
Search: 
Search
Torrent Site Tracker
TekSavvy
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code

‘Extremely Critical’ Windows holes

p2pnet.net News:- Things have been looking good for Microsoft as far as security holes were concerned. However, the picture has changed.

Secunia says it’s identified two new vulnerabilities and has tagged both of them ‘extremely critical’.

And both are actively being exploited in the wild to install adware on users’ systems, it states here.

Secunia says in the first, local resource access vulnerability can be exploited via a specially crafted URL in the ‘Location: HTTP’ header to open local files.

And in the second, a cross-zone scripting error can be exploited to execute files in the “Local Machine” security zone.

The company say it’s confirmed the holes in a fully patched system with Internet Explorer 6.0, going on, “It has been reported that the preliminary SP2 prevents exploitation by denying access.

“Successful exploitation requires that a user can be tricked into following a link or view a malicious HTML document.”

“In simple terms,” says COMPUTERWORLD here, “the link uses an unknown vulnerability to open up a local Explorer help file — ms-its:C:WINDOWSHelpiexplore.chm::/iegetsrt.htm. It delays executing anything immediately but instead uses another unknown vulnerability to run another file which in turn runs some script. This script is then used to run more script.

“And finally that script is used to run an exploit that Microsoft Corp. has been aware of since August 2003 but hasn’t patched.”

The solution? Disable Active Scripting support for all but trusted web sites, says Secunia.

HOME

One Response to “‘Extremely Critical’ Windows holes”

  1. Reader's Write Says:

    Every week they find an ‘extremely critical’ security flaw a ten year old can drive a truck through.

    I am still in awe of the millions of idiots that use this cobbled mess of an operating system for mission critical applications like basing voting machines on Windoze. (see recent stories of Diebold and how it was hacked in minutes)

    What a bunch of morons!

Leave a Reply

Please no Spam, flaming (attacking others), trolling, and posting off-topic. Thanks.

    Advertisements
MP3Rocket


Remove Spyware with AntiSpyware for Windows®