eEye Flags Another IE Code Execution Flaw

執筆者
Ryan Naraine
Ryan Naraine
Published: Aug 2, 2005
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Microsoft Corp. on Tuesday confirmed it was investigating a new “high risk” vulnerability in the widely used Internet Explorer Web browser.

The software giants acknowledgement follows the release of a brief advisory from Aliso Viejo, Calif.-based eEye Digital Security that the flaw could put millions of users at risk of code execution attacks.

“A vulnerability in default installations of the affected software allows malicious code to be executed,” eEye said in a notice placed on its Upcoming Advisories Web page.

The company rated the flaw as “high risk” and warned that users of Internet Explorer, Windows 2000, Windows 2003, Windows XP and Windows XP SP1 were affected.

“[We] can confirm that Microsoft has received a new report of a possible vulnerability through our standard vulnerability reporting mechanism. We are investigating the report and will take appropriate action to help protect customers as part of our normal security response process,” a Microsoft spokesperson said in a statement sent to Ziff Davis Internet News.

The vulnerability was brought to Microsofts attention on Monday and is among a list of six Windows flaws discovered by eEye that have not yet been patched.

/zimages/2/28571.gifClick hereto read more about eEyes discovery of IE and Outlook flaws.

One of the unpatched vulnerabilities, which affected IE and Microsoft Outlook users, is 66 days overdue, according to eEyes calculations. The company typically gives a software vendor 30 days to release a patch before determining that the fix is overdue.

All six of the unpatched flaws could lead to code execution attacks, according to eEye, and three are listed as overdue.

Under normal circumstances, Microsoft patches are released on a monthly cycle, but in an emergency, the company could release an out-of-cycle update. Since adopting the monthly patching cycle in October 2003, Microsoft has released three out-of-cycle patches, all for “critical” IE flaws.

/zimages/2/28571.gifRead morehereabout the security enhancements added to the IE 7 beta.

The latest browser bugs come at a time when Microsoft is pushing ahead with plans for a new version of its dominant IE browser. Last week, the company shipped two slightly different IE 7.0 test versions, one as part of the Windows Vista beta and another stand-alone beta to developers.

Advertisement

In Windows Vista, the new browser will include a “defense-in-depth feature” known as “low-rights.”

According to Microsoft, “low-rights IE” will back up and support several security-related browser enhancements that include technology to thwart phishing and malware attacks.

/zimages/2/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。