Older Microsoft Internet Explorer Vulnerable to Security Flaw | eWeek

Older Microsoft Internet Explorer Vulnerable to Security Flaw

Written By
Brian Prince
Brian Prince
Nov 23, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Proof-of-concept code for an attack targeting old versions of Microsoft Internet Explorer has made its way online.

According to Symantec, someone posted the code Nov. 20 to the Bugtraq mailing list. The code targets a flaw tied to how Internet Explorer (IE) uses cascading style sheet ( CSS) information. CSSis used in many Web pages to define the presentation of the sites’ content.

The flaw is known to affect IE 6 and IE 7. The most current version of the browser, IE 8, is not thought to be impacted. IE 6 and IE 7 are still widely used however, and by one estimate account for roughly 41 percent of the Web browser market share.

“The exploit currently exhibits signs of poor reliability, but we expect that a fully-functional reliable exploit will be available in the near future,” Symantec researchers noted in a blog post Nov. 21. “When this happens, attackers will have the ability to insert the exploit into Web sites, infecting potential visitors. For an attacker to launch a successful attack, they must lure victims to their malicious Web page or a Web site they have compromised. In both cases, the attack requires JavaScript to exploit Internet Explorer.”

Researchers at Vupen Security stated in an advisory that the issue is caused by a dangling pointer in the Microsoft HTML Viewer (mshtml.dll) when retrieving certain CSS/STYLE objects via the “getElementsByTagName()” method. If exploited successfully, attackers could the browser or execute arbitrary code by tricking a user into visiting a malicious web page.

As a fix, Vupen advised users to disable active scripting in the Internet and Local intranet security zones.

Microsoft could not be reached for comment.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.