[1160] in winnt
New Windows Update available for IE vulnerability.
daemon@ATHENA.MIT.EDU (James C. White/MIT)
Thu Jul 10 11:51:13 2003
Message-Id: <5.1.0.14.2.20030710114921.00b55400@hesiod>
Date: Thu, 10 Jul 2003 11:51:04 -0400
To: winpartners@mit.edu
From: "James C. White/MIT" <jcwhite@MIT.EDU>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Microsoft Warns Of Security Flaw In Windows Software
DOW JONES NEWSWIRES
(This article was originally published Wednesday)
NEW YORK -- Microsoft Corp. (MSFT) warned customers of a security flaw in
most versions of its Windows operating system that could allow an attacker
to hijack their PCs or server computers.
The Redmond, Wash., company issued a security bulletin Wednesday alerting
customers of the vulnerability and advising them to install a software fix
that it made freely available on its Web site.
A spokesman for Microsoft said the company isn't aware of any attacks that
have exploited the vulnerability.
The flaw is found in a part of the operating system that allows users to
view, import or save files as HTML documents, Microsoft said. A hacker
could cause the software to fail in such a way as to run malicious programs
on the targeted computer.
Since the HTML conversion software is used by Microsoft's Internet Explorer
Web browser, an attacker could send an e-mail with a link to a specially
crafted Web page that automatically exploits the security flaw when visited.
The vulnerability, which Microsoft described as "critical" for most
versions of Windows, is found in iterations of its operating system for
both PCs and server computers, including Windows 98, Windows XP, Windows
4.0 and Windows 2000.
The risk is less severe for the recently introduced Windows Server 2003,
which has a default security configuration that would block automatic
exploitation of this attack, the company said.