Search

  
 
Flaw discovered in IE that allows local file access


February 21 2007

Flaw discovered in IE that allows local file access

 

A researcher today unveiled an unpatched vulnerability in Internet Explorer (IE) that could allow an attacker remote access to victims' local files, but Microsoft downplayed its severity.


According to an advisory posted on XDisclose, the "critical" flaw is related to the way that IE processes different HTML tags, such as "img," "script," "embed," "object," "param," "body" and "input." The bug was discovered by Rajesh Sethumadhavan, a research engineer from India.

"By using the file protocol along with [these] tags, it is possible to access victims' local files," according to the XDisclose advisory.

The vulnerability exists in IE6 and is possible in other versions of the browser. For success, an attacker must dupe a PC user into visiting a website containing the malicious code, according to the recommendation.

A Microsoft spokesman told SCMagazine.com today the software giant has confirmed the vulnerability but that it cannot be exploited to allow an attacker to "receive files from an affected system," only to detect them.

"In addition, the attacker must know the location of the file in advance," the spokesman said. "This behaviour is by design in current versions of IE."

The revelation came less than a week after Microsoft issued a dozen patches addressing 20 vulnerabilities.


 

Reproduced from an article published by SC Magazine
© SC Magazine

The original article can be viewed here:
http://www.scmagazine.com/uk/news/article/634415/flaw-discovered-ie-allows-...

 Bookmark Digg this story

RSS feed  |  About RSS feeds

Get the Industry's top stories delivered straight to your inbox...
Firstname:

Surname:

Email:

Frequency:
 Daily  Weekly
 
 
Industry News
Case Studies
White Papers
Press Releases
Vulnerability Advisories
Monthly Newsletter Archive
Bandwidth Management
Consultancy Products
Content Control
Desktop Protection
Email Management
Encryption Solutions
Firewall/VPN Solutions
Identity and Security
Intrusion Management
Network Optimisation
Secure Remote Access
SIEM (Event correlation)
Strong Access Control
Vulnerability Management
Web Services Security
Wireless Security
About GSS
Supported Charities
Partner Accreditations
Exhibitions & Events
Contact Details
Location
Careers
Terms & Conditions of Sale
Network Penetration Testing
Web Application Testing
Managed Vulnerability Scanning
Citrix ESA
Wireless Scanning
GCSx ITHC Testing
Vulnerability Advisories
ICS Catalogue