Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
FCC chairman gives support for use of 'white spaces'
Cyber security threats grow in sophistication, subtlety and power
Ex-Google, Yahoo employees behind Hadoop startup
Ex-Enron Broadband exec pleads guilty to wire fraud
Quest's post-acquisition road map a killer for NetPro
Cisco rolls out TelePresence rental service
Willing to pay a 'Mac tax'?
Microsoft reveals critical holes in Active Directory, mainframe gateway
Intel reports record Q3 revenue
Federal employees lack tools for mobile work, study finds
Apple's new MacBooks carved from blocks of aluminum
How bad is U.S. broadband deployment?
Cisco iPrize goes to energy-efficient power grid
Cisco launches first-ever authorized CCIE training program
Novell buying Managed Objects for BSM
Security /

Microsoft, CERT disagree on Internet Explorer patch

Today's breaking news
Send to a friendFeedback

Advertisement:


A Microsoft patch aimed at fixing a previously discovered ActiveX flaw may not fully protect users against the vulnerability, according to an advisory issued Monday by Carnegie Mellon University's Computer Emergency Response Team (CERT).

But in response to the CERT advisory, a Microsoft spokesman Tuesday insisted that the patch released by the company on June 2 provides protection against the vulnerability in all circumstances where users follow basic security procedures.

The disagreement involves a little-known but potentially serious flaw that was discovered in mid-April with an ActiveX-based shortcut control in the HTML Help feature built into Microsoft's Internet Explorer Web browser. The shortcuts allow HTML Help files to link to and execute code that helps users understand how to perform certain tasks, said Shawn Hernan, a CERT member.

But under certain conditions - which are described by CERT in its advisory - the feature can be exploited by crackers to plant a malicious help file from a remote location onto a user's system. Basically, "someone who can exploit this vulnerability can (remotely) do anything you can do on your computer" if the the conditions apply, Hernan claimed.

Earlier this month, Microsoft's own description of the flaw and announcement of the patch's release acknowledged that attackers exploiting the security hole "could take any actions that the user could take, including adding, changing or deleting data, or communicating with a remote Web site."

Scott Culp, a Microsoft security program manager, said the company's patch eliminates the vulnerability by only allowing an HTML Help file to use shortcuts if the file resides on a user's PC. That should provide ample protection as long as users stick to basic security practices such as having a secure firewall and not accepting files from unknown sources, he said.

The security flaw can only be exploited under certain very rare circumstances and even then only if the user actively downloads a malicious file from a remote location, Culp added. "CERT's advisory oversimplifies the steps that an attacker would need to exploit the flaw," he said. "The scenario they're postulating would open users up to a far broader range of security issues above and beyond this vulnerability."

But in its advisory, CERT claimed the preconditions needed for the vulnerability to be exploited weren't all that uncommon and posed a greater risk than Microsoft describes.

"For some sites, the patch provided by Microsoft is adequate," CERT said in the advisory. "For others, particularly those sites using non-Microsoft networking products, the patch does not provide complete protection." Users need to understand their network's configuration prior to deciding which, if any, changes are required beyond installing the patch, CERT added.

For more enterprise computing news, visit Computerworld online. Story copyright © 2000 Computerworld, Inc. All rights reserved.

Advertisement:

RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.