Microsoft Investigates IE 8 Security Vulnerability Report

執筆者
Brian Prince
Brian Prince
Published: Sep 7, 2010
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Microsoft has confirmed it is investigating reports of a flaw in Internet Explorer 8 that could be exploited to attack users.

A description of the vulnerability was posted Sept. 3 to the Full Disclosure mailing list by Google Information Security Engineer Chris Evans. In a proof-of-concept, Evans demonstrated how the bug-a CSS (Cascading Style Sheets) cross-origin theft issue-could be used to force a victim to send a Twitter message.

“This is purely an IE bug; there is no fault on behalf of Twitter and there is no reasonable workaround,” Evans wrote.

Cross-origin CSS attacks are believed to have first been described back in 2002, according to a recently published paper. (PDF) The other major browser vendors-Apple, Google, Mozilla and Opera Software-have fixed the problem in question in their browsers, but Microsoft has not, Evans wrote on Full Disclosure, even though there is evidence the company has known of the problem “since at least 2008.”

He declined to comment further when asked by eWEEK. But in an August blog post, Evans said IE was the browser most vulnerable to the CSS flaw.

“I have PoCs which will steal your Webmail’s XSRF token, with follow-on loss of account integrity and confidentiality,” he posted at the time. “It’s a nasty attack: E-mail someone a link and if they click it, they are owned with a pure browser cross-origin bug.”

When asked about the flaw, Microsoft responded that it was looking into the reports and would take appropriate action.

“Microsoft is investigating new public claims of a possible vulnerability in Internet Explorer,” Jerry Bryant, group manager of response communications for Microsoft Security Response Center, said in a statement Sept. 7. “We’re currently unaware of any attacks trying to use the claimed vulnerability or of customer impact. Once we’re done investigating, we will take appropriate action to help protect customers. This may include providing a security update through the monthly release process, an out-of-cycle update or additional guidance to help customers protect themselves.”

Advertisement

Earlier versions of IE may be affected as well, according to Evans.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。