Microsoft
Microsoft has promised to fix a problem in IE7's handling of uniform resource indicators

Microsoft comes clean on URI holes

Company vows to fix address handling flaw

Written by Shaun Nichols in California

Microsoft is to issue a fix for a bug in Internet Explorer 7 that leaves users vulnerable to attack.

Members of Microsoft's Secure Windows Initiative team explained the issue in an article posted to a company blog.

The problem exists in IE7's handling of uniform resource indicators (URIs) in Windows XP and Server 2003.

The URI is the first part of an address, used to specify which application runs a file or link. One example is the 'mailto:' command which launches an email client.

After the URI link is clicked, Windows calls a component known as 'ShellExecute' which then runs the URI instructions.

In recent months, researchers have outlined vulnerabilities in Firefox and Internet Explorer that could allow an attacker to execute malicious code and compromise a target system.

Mozilla recently issued an update for Firefox that addresses the issue, and Microsoft is saying it will need to do the same.

Previous versions of Internet Explorer checked the URI within the browser. If an address was malformed or invalid, the process would fail and the URI would not run.

With the new version of the browser, however, a malformed URI is "cleaned up " in order to be run. This, say researchers, allows attackers to run potentially malicious code hidden within the URI.

The Secure Windows Initiative developers said that a security component prevents Windows Vista from running the URI scripts, protecting IE7 from the attack on Vista. No such protections exist Within IE7 on Windows XP and 2003, however.

The developers believe that the ShellExecute component will need to be redesigned in order to be "more strict" in its handling of URLs.

Microsoft gave no expected release date for the update, and recommended that developers take matters into their own hands to secure their applications in the meantime.

Tags:

Further reading

Microsoft rolls out nine fixes

Six 'critical' vulnerabilities patched in October update   More...

Microsoft takes piracy locks off IE7

Windows Genuine Advantage no longer required for browser   More...

XP restore cripples Windows Update

Silent update leaves restored users stranded   More...

Windows XP goes into extra time

Availability extended to 30 June 2008   More...

Related articles

Attackers take aim at IE7 flaw

Microsoft reports new URI attacks   More...

Mozilla seals off URI flaws again

Firefox update fixes vulnerabilities in resource handler   More...

Mozilla issues 'critical' Firefox fixes

Update addresses a number of security issues   More...

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement