Microsoft IE flaws
Microsoft IE flaws

Warning issued on new IE flaws

Safety experts advise switching browsers as three 'Zero Day' flaws hit Microsoft

Written by Iain Thomson

Three new flaws for which no patch exists - so-called 'Zero Day' flaws - have been identified in Microsoft's Internet Explorer.

Like Sasser, two of the three vulnerabilities need no user intervention and can be downloaded just by logging on to the internet.

The third allows a false web address to be embedded in an email to misdirect users to a phishing site, which then attempts to capture user information.

The US Computer Emergency Readiness Team warned of the phishing flaw late on Friday, while security firm Ubizen highlighted the other two after being in contact with a researcher investigating computers where pornographic banners had been inserted into the browser toolbar.

Ubizen has advised computer users to switch to alternative web browsers like Netscape or Mozilla for the moment.

"[Changing browser is] a harsh workaround but at the end of the day it'll work," said Dick Van Droogenbroeck, senior security assessment engineer at Ubizen's Security Intelligence Laboratory.

"As there is no fix available, the hacker community will seek to massively exploit these vulnerabilities. Hit the wrong web page and it's over and out."

No patches are available as yet.

In a statement, Microsoft said: "Microsoft is actively investigating these reports, to determine the appropriate course of action to protect our customers. This might include providing a fix through our monthly release process or an out-of-cycle security update, depending on customer needs.

The software giant also promised to "work aggressively with law enforcement to help prosecute individuals or organisations" who exploit the flaws.

Microsoft urged customers to review its safe browsing tips. Details of how to strengthen browser security are also available here.

Tags:

Further reading

Microsoft warns of three critical IE flaws

Hackers could take complete control of an affected system   More...

Microsoft warns on IIS 5 and IE attack

Users advised to disable JavaScript and download latest security updates   More...

Security

The latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.   More...

Online phishing uses new bait

One click sends unwary users to fake websites   More...

Related articles

Mozilla fixes Firefox flaws

Most users automatically updated   More...

vnunet.com analysis: Browser wars changing security game

Variety and competition bring new protections and new threats   More...

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Black hat IPS reverse engineering poses 'serious threat'

Gartner warns enterprises to be on their guard   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement