Tune XP - tune-up, tweak and optimize your Windows XP!
  
  
OOKO Search
Smart search for shareware and freeware
Backup
Completely protect yourself from fatal system failure
Security and Privacy
Enhance your security and protect your privacy
PC Monitoring
PC monitoring and surveillance software
Disk Management
Tune-up, tweak, optimize, fix problems on your hard disk
Password Recovery
Recover forgotten or lost passwords
System Tweaking
Tune-up, tweak and optimize your Windows system

Drag-and-drop flaw in IE reported

Security analysts and vendors are reporting a flaw in Microsoft Corp.'s Internet Explorer browser that could allow malicious code to run and allow a hacker to take control of a user's computer.

Microsoft was informed of a vulnerability with IE's drag-and-drop function in August 2005, after it was first found by Matthew Murphy, said Noam Rathaus, chief technical officer at Beyond Security Ltd. in Netanya, Israel today. The company, which helped Murphy report the flaw to Microsoft last year, runs an independent security site called SecuriTeam.

Websense Inc., which also issued a warning today, wrote that a specially crafted Web site could trick a user into dragging and dropping an item from one window to the other. After the user released the mouse in the newly focused window, code could run without the user's consent, Websense said.

Microsoft said it wouldn't issue an immediate patch, but will instead wait to issue a fix in Service Pack 2 for Windows Server 2003 and Windows XP Service Pack 3, Rathaus said.

Microsoft officials were not immediately available for comment.

The SecuriTeam site went public with the vulnerability after consulting Microsoft, Rathaus said. SecuriTeam detailed three methods to prevent the flaw from being exploited.

SecuriTeam's advisory criticized Microsoft's decision not to issue a patch, saying the company's "conclusion appears fundamentally inconsistent with the way related issues were handled by Microsoft."

Further, Websense said the vulnerability is not as easy to exploit as some others, but a risk remains.

"They [Microsoft] don't see the issue being that important," Rathaus said. "They are not going to fix it any time soon."

As part of its monthly patch update, Microsoft plans to release seven fixes tomorrow for Windows Media Player, Windows and Microsoft Office.

Go back Go Back

Source: Computerworld.com

Tune XP CD-ROM
Give your computer a chance to show all of its potential with this new Tune XP collection of Windows XP tips and software, which will help you manage, secure, backup and tweak your system for good. This package will bulletproof your computer from many potential disasters and teach you more about your PC.

Learn more
Order TuneXP CD

What's Hot

Acronis DriveCleanser
Acronis PartitionExpert 2003
Ashampoo WinOptimizer Suite
Handy Backup
iOpus Password Recovery XP
SpyAgent
SpyBuddy