Subscribe:Posts Comments

You Are Here: Home » Software, Windows Vista » IE 7, Vista Bug Reports Have MS Digging

Microsoft is investigating two recently disclosed security vulnerabilities that affect Internet Explorer 7 and Windows Vista, the company said Monday. The vulnerabilities aren’t considered high-risk, yet they affect the latest releases of Microsoft’s Web browser and operating system software.

Microsoft has promoted the security of both IE 7 and Windows Vista. The flaws could let attackers get their hands on sensitive user information, security experts have warned. The French Security Incident Response Team said in an alert that the IE vulnerability, which also affects IE 6, could be exploited in phishing attacks, scams that try to trick people into giving up sensitive information such as credit card data and Social Security numbers.

The problem exists because of an error in the way the browser handles certain “onunload” events, the security monitoring company said. Attackers could exploit the issue to spoof the browser address bar, FrSirt said. The Windows issue is due to a problem with a component that does not properly validate user permissions. This could be exploited by an attacker with access to the machine to get information on protected files, according to a second FrSirt alert.

The problem affects Windows Vista, XP, 2000 and Windows Server 2003, FrSirt said. Microsoft is looking into both vulnerabilities, which were made public last week. Neither of the flaws has been used in any attacks and exploiting the issues is hard, a company representative said.

You can follow us on Twitter or join our Facebook Fan Page for more updates like this.



5 Comments

Leave a Reply