Researchers Find Flaws In IE Patch


CRN logo By Marcia Savage

2:42 PM EDT Tue. May. 21, 2002
From the May 21, 2002 issue of CRN
The massive patch Microsoft issued last week for Internet Explorer fails to fix all of the vulnerabilities it targeted, security researchers said.

Researchers at Vigilinx said after installing the cumulative patch, cross-site scripting vulnerabilities remained in legacy versions of IE, including versions 5.01 and 5.5.

Additional testing of the patch showed weaknesses in the information disclosure vulnerability, the firm said.

Microsoft released the patch last week to fix six new vulnerabilities in IE and said the most serious flaw could allow an attacker to run any code he or she chooses. IE versions 5.01, 5.5 and 6.0 are affected.

Another company, GreyMagic Software, said the patch failed to correct one of the vulnerabilities.

A Microsoft spokesman said the developer updated its original bulletin about the patch with some wording changes. But he said the patch is effective.

"The patch works," he said. "It fixes the vulnerabilities."

Microsoft is investigating reports of additional vulnerabilities in IE that have come out since the patch was released, he added.

 
Channelweb : Promofinder
FEATURED PROMOTIONS
Avnet 0% Lease Promotion
The Avnet Capital Solutions “0% Lease Promotion” has been extended to December 31, 2009! This offering significantly reduces ...
Double Your Money!
Cash Rewards - DOUBLED!
RELATED BLOG >>
Photo
LogLogic takes complex log data and turns it into something manageable.
ADVERTISEMENT




CHANNEL SERVICES >>