Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Flaws in IE Upgraded to Critical Rating

    Written by

    Dennis Fisher
    Published December 23, 2002
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Security issues continue to haunt Microsoft Corp., as the software company recently disclosed several serious vulnerabilities in its Java implementation and was forced to restate the severity of two flaws in Internet Explorer.

      The Redmond, Wash., company earlier this month upgraded the severity rating of a vulnerability in the way that IE handles PNG (Portable Network Graphics) images. The browser fails to correctly check the parameters of PNG files when it opens them, which can result in a buffer overrun. Other Microsoft applications, including Office products, use IE to render PNG images, and using this vulnerability against one of these applications could allow an attacker to run code on a users machine.

      In its original advisory Nov. 20, Microsoft gave this vulnerability a rating of “important” but on Dec. 12 escalated it to “critical,” the highest rating. The change resulted from research by eEye Digital Security Inc., which discovered that it was possible to run code on remote users systems.

      The first version of the bulletin said that an attacker could force IE to crash only by exploiting this flaw. eEye published its advisory on the BugTraq security mailing list Wednesday.

      This was the second time in about a week that Microsoft had moved to upgrade the severity rating of a vulnerability. The company Dec. 4 released a cumulative patch for IE, which also fixes a new flaw that the company said could allow a Web site to access information on users machines.

      The company rated the vulnerability as “moderate” and said that attackers could read but not change files on a vulnerable machine or run without parameters an executable file already present on the computer. However, a well-known security researcher posted a message to BugTraq disputing Microsofts assessment of the vulnerability, saying that the flaw is much more severe than the company reported.

      “Microsoft has given this vulnerability a maximum severity rating of moderate. Great, so arbitrary command execution, local file reading and complete system compromise is now only moderately severe, according to Microsoft,” wrote Thor Larholm, a Danish security researcher with PivX Solutions LLC, a Newport Beach, Calif., security consultancy.

      Microsoft later upgraded the severity rating to “critical.”

      ROUGH PATCHES

      Recent security problems for Microsoft

      • Dec. 4 Microsoft issues patch for object-caching flaw in IE
      • Dec. 6 Microsoft upgrades severity of object-caching flaw
      • Dec. 11 Microsoft issues fix for eight flaws in Virtual Machine
      • Dec. 12 Microsoft forced to upgrade severity of PNG flaw to “critical”

      Microsoft also recently released fixes for eight new vulnerabilities in its VM (Virtual Machine) software, the most serious of which gives attackers the ability to take control of vulnerable PCs. VM runs Java applets in Windows environments and ships with most versions of Windows and IE.

      The most dangerous of the new flaws lies in the way that Java programs access COM (Component Object Model) objects. The vulnerability allows untrusted applets to access some COM objects that make it possible for an attacker to compromise a target system. Two of the other vulnerabilities allow a Java applet to disguise the location of its code base. This, in turn, could allow an applet on a Web site to mask its location and act as if it were located on a users machine or network.

      There is also a vulnerability that results from the VMs failure to prevent applets from calling a certain set of APIs that provide database access methods. An attacker who exploits this flaw could take any action on a database file, limited only by the local users permissions.

      The four other vulnerabilities are less serious.

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×