MS confirms 'F1 to pwn' IE bug

  • Follow


<Quote>
Microsoft has confirmed that an unpatched Internet Explorer
vulnerability makes it potentially dangerous to press F1 if you are
running earlier versions of Windows.

A security bug in the VBScript technology bundled with Internet
Explorer means that it might be possible to create a web site that
displays a specially crafted dialog box that pushes malware providing
a victim is tricked into pressing the F1 (help menu) key while viewing
a booby-trapped site using Internet Explorer. The novel exploit
technique works on older versions of Windows (Win 2000, XP and Server
2003). As previously reported, Vista, Windows 7 and Windows Server
2008 are immune.
</Quote>

http://www.theregister.co.uk/2010/03/03/ms_confirms_ie_bug/
0
Reply nessuno7491 (872) 3/4/2010 3:10:33 PM

nessuno wrote:

> <Quote> Microsoft has confirmed that an unpatched Internet Explorer 
> vulnerability makes it potentially dangerous to press F1 if you are 
> running earlier versions of Windows.
> 
> A security bug in the VBScript technology bundled with Internet 
> Explorer means that it might be possible to create a web site that 
> displays a specially crafted dialog box that pushes malware providing
> a victim is tricked into pressing the F1 (help menu) key while
> viewing a booby-trapped site using Internet Explorer. The novel
> exploit technique works on older versions of Windows (Win 2000, XP
> and Server 2003). As previously reported, Vista, Windows 7 and
> Windows Server 2008 are immune. </Quote>
> 
> http://www.theregister.co.uk/2010/03/03/ms_confirms_ie_bug/

Linux has been quite immune for some time.

-- 
HPT
0
Reply High 3/8/2010 6:58:23 AM


1 Replies
108 Views

(page loaded in 0.226 seconds)


Reply: