Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Windows Secrets>IE patched again, but is still insecure

IE patched again, but is still insecure

Tweet

Chris mosby By Chris Mosby

This Patch Tuesday, Microsoft has once again fixed several flaws in IE — but, as usual, there are other holes still unpatched.

As discovered earlier this month, IE is wide open to a pretty severe cross-domain flaw that can allow a hacker to do just about anything to your computer.


IE is vulnerable to cross-domain attacks

Versions 6 and 7 of Internet Explorer have a flaw in their “cross-domain” security models. This can allow, among other things, one Web site to access information from another Web site when you transition from one page to another.

This poses a large threat to corporations that allow their users to freely surf the Internet. A user might visit a hacked Web site that could carry out various attacks, including setting or reading browser cookies, reading or modifying form submissions, and executing hacker programs, which would have administrative rights. This flaw has been confirmed on fully patched versions of IE in multiple versions of Windows.

Strangely, the FrSIRT (French Security Incident Response Team) listing of this flaw states that the vulnerability has been fixed by Microsoft’s June 12 MS07-033 patch for IE. However, Microsoft’s bulletin doesn’t claim this flaw as part of the fix list for that patch. (The MS bulletin doesn’t include the problem’s CVE number, a tracking system for threats that is hosted and defined by the MITRE Corp.

No other security sources make the same claim as FrSIRT, at the time of this writing. Testing I’ve done on a fully patched XP system with the demo page that’s provided by Michal Zalewski, the person who discovered this flaw, doesn’t support FrSIRT’s claim either.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.

Related posts:

  1. Patched IE still has security holes
  2. MS RAS patch patched
  3. Critical Firefox vulnerability patched
  4. Flaw in Windows ISA server error pages
  5. NTFS Files Insecure?
= Paid content

All Windows Secrets articles posted on 2007-06-14:

  • Top Story Practice ‘safe surfing’ with public Wi-Fi signals
  • Known Issues Connecticut teacher gets a second chance
  • Wacky Web Week E-cards for any odd occasion
  • PC Tune-Up VMware is a superior alternative to Virtual PC
  • Windows Secrets IE patched again, but is still insecure
  • Patch Watch MS slyly installs WGA via updates, again
  •  Show all articles on a single page
E-books

We’ve pored through years of back issues, picking the best tips, to create these ebooks:

E-book series
  • PC Maintenance Guide
  • PC Security Guide
  • Windows 7 Guide Vol 1
  • Windows 7 Guide Vol 2
  • Win XP Survival Guide
See the e-book series
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.21
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Don’t pay for software you don’t need — Part 2 4.10
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb