Welcome Guest ( Log In | Register )

  Recent Software News
Microsoft called top PDA software m...
Skype Makes Cell Calls Free
Windows Installer 3.0 Redistributab...
Mozilla Firefox 1.0 Released
GMail Drive v1.0.3
  Recent Gaming News
Halo 2 brings in $125 million for M...
Sims the Urbz Launches
Sims 2 Addon Packs
Microsoft & Xbox Live Banning
Xbox 2 takes shape as ATI rolls out...
  Recent Reviews
 · CoolerMaster Aerogate 3 A...
 · CoolerMaster AquaGate Wat...
 · OCZ Copper BGA Ramsinks
 · Mapower Warps Portable 3....
 · Vantec - PCI & RAM Slot P...
  Recent Forum Posts
Leadtek A350XT TDH and overclo...
FX5900U vs 9800Pro
Google Gmail Invites
Doom 3 SDK Released
Windows XP Sp2 Problems
  Announcement

Welcome to AusPCWorld - Australia's Leading PC Technology News & Reviews site.



> AusPCWorld > Tech News > Critical Flaw Found in Windows XP SP2






   
Critical Flaw Found in Windows XP SP2
Posted by Chris on 22 Aug 2004 - 13:24 0 comments
Previous Post | Tech News | Next Post
 
Security firm Secunia has detailed a new flaw in Internet Explorer that affects users running Windows XP Service Pack 2. The vulnerability involves drag-and-drop, which can be used within a Web page to place a malicious program in the Windows startup folder.

Secunia has branded the issue "highly critical" and says it comes from "insufficient validation of drag and drop events issued from the 'Internet' zone." Users are advised to disable Active Scripting, or use a Web browser other than Internet Explorer.

The security researcher who discovered the flaw has posted proof-of-conccept code, which involves dragging an image across a Web page. But Secunia says it could be simplified to require just one mouse click. Microsoft, however, brushed off concerns over the potential issue. "Given the significant amount of user action required to execute an attack, Microsoft does not consider this to be a high risk for customers," the company said.

View: Betanews



There are 0 additional comments, Post a comment | View printable post | Open/Close All Comments


Add A new comment
Name: (Register)
Email: (optional)
Quick HTML: (help)
  Close current tag   Standard Mode
  Close all tags   Enhanced Mode
Comment:


Smilies
(help)
Parse URL's: (will automatically add [url] [/url] round the web addresses in your comment)