<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; internet explorer vulnerability</title>
	<atom:link href="http://www.ghacks.net/tag/internet-explorer-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Mon, 23 Nov 2009 22:22:46 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Microsoft Internet Explorer Security Update</title>
		<link>http://www.ghacks.net/2009/07/28/microsoft-internet-explorer-security-update/</link>
		<comments>http://www.ghacks.net/2009/07/28/microsoft-internet-explorer-security-update/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 20:40:10 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[internet explorer patch]]></category>
		<category><![CDATA[internet explorer security]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[web browser]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=14866</guid>
		<description><![CDATA[Microsoft has released a critical security fix for their Internet Explorer web browsers. The vulnerability, actually its more than one that are patched by the cumulative patch, affect most Internet Explorer still in use by users worldwide including Internet Explorer 6, Internet Explorer 7 and the latest version Internet Explorer 8. The vulnerability does only [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/internet_explorer_8.png" alt="internet explorer 8" title="internet explorer 8" width="128" height="128" class="alignleft size-full wp-image-11776" />Microsoft has released a critical security fix for their <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a> web browsers. The vulnerability, actually its more than one that are patched by the cumulative patch, affect most Internet Explorer still in use by users worldwide including Internet Explorer 6, Internet Explorer 7 and the latest version Internet Explorer 8. The vulnerability does only affect Internet Explorer versions running on Windows operating systems. The most popular Microsoft operating systems are all affected including Windows XP, Windows Vista and even the soon to be released <a href="http://windows7news.com/">Windows 7</a>.</p>
<p><span id="more-14866"></span><br />
<blockquote>This security update is being released out of band in conjunction with Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx">MS09-035</a>, which describes vulnerabilities in those components and controls that have been developed using vulnerable versions of the Microsoft Active Template Library (ATL). As a defense-in-depth measure, this Internet Explorer security update helps mitigate known attack vectors within Internet Explorer for those components and controls that have been developed with vulnerable versions of ATL as described in Microsoft Security Advisory (<a href="http://www.microsoft.com/technet/security/advisory/973882.mspx">973882</a>) and Microsoft Security Bulletin MS09-035.</p>
<p>This security update also resolves three privately reported vulnerabilities in Internet Explorer. These vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p>
<p>This security update is rated Critical for Internet Explorer 5.01 and Internet Explorer 6 Service Pack 1, running on supported editions of Microsoft Windows 2000; Critical for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 running on supported editions of Windows XP; Critical for Internet Explorer 7 and Internet Explorer 8 running on supported editions of Windows Vista; Moderate for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 running on supported editions of Windows Server 2003; and Moderate for Internet Explorer 7 and Internet Explorer 8 running on supported editions of Windows Server 2008. For more information, see the subsection, Affected and Non-Affected Software, in this section.</p></blockquote>
<p>Windows users should make sure to download the security update as soon as possible. It is available at the usual sources including automatic updates, Windows Update or Microsoft Update.</p>

	Tags: <a href="http://www.ghacks.net/tag/internet-explorer-patch/" title="internet explorer patch" rel="tag">internet explorer patch</a>, <a href="http://www.ghacks.net/tag/internet-explorer-security/" title="internet explorer security" rel="tag">internet explorer security</a>, <a href="http://www.ghacks.net/tag/internet-explorer-vulnerability/" title="internet explorer vulnerability" rel="tag">internet explorer vulnerability</a>, <a href="http://www.ghacks.net/tag/internet-explorer/" title="internet-explorer" rel="tag">internet-explorer</a>, <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/web-browser/" title="web browser" rel="tag">web browser</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/03/13/real-player-internet-explorer-vulnerability/" title="Real Player Internet Explorer vulnerability (March 13, 2008)">Real Player Internet Explorer vulnerability</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/06/18/microsofts-internet-explorer-comparison-chart/" title="Microsoft&#8217;s Internet Explorer Comparison Chart (June 18, 2009)">Microsoft&#8217;s Internet Explorer Comparison Chart</a> (23)</li>
	<li><a href="http://www.ghacks.net/2009/02/11/microsoft-february-security-updates/" title="Microsoft February Security Updates (February 11, 2009)">Microsoft February Security Updates</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/05/08/log-into-multiple-accounts-at-the-same-site-with-internet-explorer-8/" title="Log Into Multiple Accounts At The Same Site With Internet Explorer 8 (May 8, 2009)">Log Into Multiple Accounts At The Same Site With Internet Explorer 8</a> (9)</li>
	<li><a href="http://www.ghacks.net/2009/07/07/internet-explorer-vulnerability-fix/" title="Internet Explorer Vulnerability Fix (July 7, 2009)">Internet Explorer Vulnerability Fix</a> (5)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/07/28/microsoft-internet-explorer-security-update/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Internet Explorer Vulnerability Fix</title>
		<link>http://www.ghacks.net/2009/07/07/internet-explorer-vulnerability-fix/</link>
		<comments>http://www.ghacks.net/2009/07/07/internet-explorer-vulnerability-fix/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 09:04:39 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[internet explorer patch]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[microsoft fix it]]></category>
		<category><![CDATA[microsoft video activex control]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[windows server 2003]]></category>
		<category><![CDATA[windows-xp]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=14190</guid>
		<description><![CDATA[Microsoft has released a security advisory about a vulnerability in Microsoft Video ActiveX Control which can be exploited remotely in Internet Explorer. The vulnerability advisory states that Microsoft is aware that attackers are trying to exploit the vulnerability. Internet Explorer users are therefor advised to fix the vulnerability as soon as possible to prevent possible [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/07/internet_explorer_vulnerability.jpg" alt="internet explorer vulnerability" title="internet explorer vulnerability" width="154" height="72" class="alignleft size-full wp-image-14191" />Microsoft has released a security advisory about a vulnerability in Microsoft Video ActiveX Control which can be exploited remotely in <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a>. The vulnerability advisory states that Microsoft is aware that attackers are trying to exploit the vulnerability. Internet Explorer users are therefor advised to fix the vulnerability as soon as possible to prevent possible attacks on their computer system.</p>
<p>The security vulnerability affects only Windows XP and Windows Server 2003 systems. Computer systems running Windows Vista, Windows Server 2008 or <a href="http://windows7news.com/">Windows 7</a> are not affected because &#8220;the ability to pass data to this control within Internet Explorer&#8221; is restricted in these operating systems.</p>
<p><span id="more-14190"></span>A successful attack will give the attacker the same user rights as the currently logged in user. Microsoft has issued a <a href="http://www.microsoft.com/technet/security/advisory/972890.mspx">workaround</a> for the Internet Explorer vulnerability that can be applied manually or using <a href="http://support.microsoft.com/kb/972890">Microsoft Fix It</a>.</p>
<p>The fastest way to patch the security vulnerability is to use the Microsoft Fix It script that will perform all the actions of the workaround automatically. The fix will basically remove support for the ActiveX Control in Internet Explorer. This should not have any impact on the web browser&#8217;s functionality according to Microsoft.</p>

	Tags: <a href="http://www.ghacks.net/tag/internet-explorer-patch/" title="internet explorer patch" rel="tag">internet explorer patch</a>, <a href="http://www.ghacks.net/tag/internet-explorer-vulnerability/" title="internet explorer vulnerability" rel="tag">internet explorer vulnerability</a>, <a href="http://www.ghacks.net/tag/internet-explorer/" title="internet-explorer" rel="tag">internet-explorer</a>, <a href="http://www.ghacks.net/tag/microsoft-fix-it/" title="microsoft fix it" rel="tag">microsoft fix it</a>, <a href="http://www.ghacks.net/tag/microsoft-video-activex-control/" title="microsoft video activex control" rel="tag">microsoft video activex control</a>, <a href="http://www.ghacks.net/tag/security-advisory/" title="security advisory" rel="tag">security advisory</a>, <a href="http://www.ghacks.net/tag/windows-server-2003/" title="windows server 2003" rel="tag">windows server 2003</a>, <a href="http://www.ghacks.net/tag/windows-xp/" title="windows-xp" rel="tag">windows-xp</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/07/28/microsoft-internet-explorer-security-update/" title="Microsoft Internet Explorer Security Update (July 28, 2009)">Microsoft Internet Explorer Security Update</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/03/13/real-player-internet-explorer-vulnerability/" title="Real Player Internet Explorer vulnerability (March 13, 2008)">Real Player Internet Explorer vulnerability</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/08/11/list-of-microsoft-fix-it-solutions/" title="List Of Microsoft Fix It Solutions (August 11, 2009)">List Of Microsoft Fix It Solutions</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/03/17/internet-explorer-virtual-pc-images/" title="Internet Explorer Virtual PC Images (March 17, 2008)">Internet Explorer Virtual PC Images</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/04/01/internet-explorer-8-fixes/" title="Internet Explorer 8 And 64-bit Windows Fixes (April 1, 2009)">Internet Explorer 8 And 64-bit Windows Fixes</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/07/07/internet-explorer-vulnerability-fix/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Real Player Internet Explorer vulnerability</title>
		<link>http://www.ghacks.net/2008/03/13/real-player-internet-explorer-vulnerability/</link>
		<comments>http://www.ghacks.net/2008/03/13/real-player-internet-explorer-vulnerability/#comments</comments>
		<pubDate>Thu, 13 Mar 2008 12:32:17 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[real player]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2008/03/13/real-player-internet-explorer-vulnerability/</guid>
		<description><![CDATA[Internet Explorer with an installed version of Real Player beware. A vulnerability has been discovered recently which could allow remote code execution. According to Zdnet users should either switch browsers for the time until an patch is released or disabling killbits for two Active X classes. They forgot to mention the third option which would [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a> with an installed version of Real Player beware. A vulnerability <a href="http://www.zdnet.com.au/news/software/soa/RealPlayer-flaw-Stop-using-Internet-Explorer/0,130061733,339286701,00.htm?feed=rss">has</a> been discovered recently which could allow remote code execution. According to Zdnet users should either switch browsers for the time until an patch is released or disabling killbits for two Active X classes. They forgot to mention the third option which would be to uninstall Real Player (temporarily).</p>
<p>Affected are all Real Player versions running under Internet Explorer. Microsoft <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;240797&#038;sd=tech">has</a> an article up that explains Killbits and what they do. They basically prevent Active X controls from being loaded in Internet Explorer. I still would recommend to either switch to <a href="http://www.ghacks.net/tag/firefox/">Firefox</a> or <a href="http://www.ghacks.net/category/browsing/opera/">Opera</a> temporarily or uninstall Real Player for the time until a security patch has been created.</p>
<blockquote><p>Researcher Elazar Broad has posted to the Full Disclosure mailing list a so-called heap overflow vulnerability that makes it possible for an attacker to modify heap blocks after they are freed and overwrite certain registers.</p></blockquote>
<p><span id="more-3502"></span>The killbits that should be disabled are the following:</p>
<ul>
<li>2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93</li>
<li>
CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA</li>
</ul>
<p>This will definitely have the effect that some Real Player functions will stop working properly.</p>

	Tags: <a href="http://www.ghacks.net/tag/internet-explorer-vulnerability/" title="internet explorer vulnerability" rel="tag">internet explorer vulnerability</a>, <a href="http://www.ghacks.net/tag/internet-explorer/" title="internet-explorer" rel="tag">internet-explorer</a>, <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/real-player/" title="real player" rel="tag">real player</a>, <a href="http://www.ghacks.net/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/07/28/microsoft-internet-explorer-security-update/" title="Microsoft Internet Explorer Security Update (July 28, 2009)">Microsoft Internet Explorer Security Update</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/06/27/you-better-stop-using-internet-explorer-for-now/" title="You better stop using Internet Explorer for now (June 27, 2008)">You better stop using Internet Explorer for now</a> (18)</li>
	<li><a href="http://www.ghacks.net/2007/10/06/validation-removed-from-internet-explorer-7/" title="Validation removed from Internet Explorer 7 (October 6, 2007)">Validation removed from Internet Explorer 7</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/08/30/use-multiple-internet-explorer-versions-simultaneously/" title="Use Multiple Internet Explorer Versions Simultaneously (August 30, 2008)">Use Multiple Internet Explorer Versions Simultaneously</a> (10)</li>
	<li><a href="http://www.ghacks.net/2008/08/29/uninstall-internet-explorer-8/" title="Uninstall Internet Explorer 8 (August 29, 2008)">Uninstall Internet Explorer 8</a> (33)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/03/13/real-player-internet-explorer-vulnerability/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
