Microsoft Warns of IE Flaw that Could Expose Local Files
Microsoft Warns of IE Flaw that Could Expose Local Files
Microsoft issued a Security Advisory (980088) to warn users of a vulnerability in Internet Explorer (shocking) that could potentially expose all local files on a filesystem with a known name and location.
The vulnerability was discussed and proof of concept code was written and demonstrated at the Black Hat DC conference by Jorge Luis Alvarez Medina, a security consultant with Core Security Technologies.
Microsoft responded with details and causes of the vulnerability, most notably pointing to disabling the Protected Mode within IE or running versions of IE that don’t include a Protected Mode. This amounts to vulnerability across Internet Explorer 5.01 and IE6 SP1 on Windows 2000 SP4, as well as IE6, IE7, and IE8 on supported editions of Windows XP and Windows Server 2003. However, Protected Mode is running by default on IE7 and IE8 on Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 and prevents the issue.
Microsoft noted that they are unaware of attacks using the vulnerability and recommended users upgrade to the latest version of IE. You can find more details in the security advisory and knowledge base article to make sure you are protected.
More like this
![]()
QUINTIX256
February 04, 2010 at 9:04pm
Or is this a different protected mode that has nothing to do with x86 proteced mode memory management?
You can have your recession. I'm not participating.
Featured Content
This month's issue
Feature
Feature
How-To
Build It
Most Commented Articles
Latest Max PC Tweets
- maximumpc: Analysts: 9-Inch Kindle Fire This Summer http://t.co/QDYApwCZ1 day 1 hour ago
- maximumpc: Micron: DRAM Prices Likely as Low as They're Going to Get http://t.co/fFUWuFOm1 day 4 hours ago
- maximumpc: Yar, Mateys! All Of Pirate Bay Made Available As A Single 90MB Zip File http://t.co/j5LHlXEZ1 day 6 hours ago














