Internet Explorer

  • Internet Explorer 8
  • Internet Explorer
  • All forums
Question

31 January 2011 Microsoft warning over browser security flaw.____31 January 2011 Microsoft warning over browser security flaw.____

I have received this information on Facebook ..... is it accurate, or is it SPAM? I am new to this so not sure how to recognise authentic Microsoft information.

Don't want to download something I shouldn't !! I am not sure what IE version mine is.

 

31 January 2011 Microsoft warning over browser security flaw.

Microsoft has issued a "critical" warning over a newly-discovered flaw in Windows.

In a security advisory, the company warned of a loophole that could be used by malicious hackers to steal private information or hijack computers.

The bug potentially affects every user of the Internet Explorer web browser - around 900 million people worldwide.

Microsoft has issued a software patch to defend against attacks, and said it was working to develop a long-term fix.

The security advisory, which was published on Friday, details how the vulnerability can be used to manipulate users and take over their machines.

Although the flaw is actually inside Windows itself, it only appears to affect the way that Internet Explorer handles some web pages and documents.

Microsoft admitted that the problem meant users could easily be fooled into downloading malicious files by doing something as simple as clicking on a web link.

"When the user clicked that link, the malicious script would run on the user's computer for the rest of the current Internet Explorer session," wrote Microsoft representative Angela Gunn in awebsite announcement accompanying the advisory.

Once the computer had been hijacked, hackers could use it to steal personal data or send users to fake websites, she added.

"Such a script might collect user information, e.g e-mail, spoof content displayed in the browser or otherwise interfere with the user's experience."

Although Microsoft said it had seen no evidence that the glitch had already been exploited by hackers, it warned that research had shown it was a serious threat.

And while it has not been able to remove the bug itself, it issued a "fix it" security patch to block any attempts to use it.

All Windows users - particularly those who use Internet Explorer - are being urged to download the fix while the company's security team develop a way to plug the hole permanently.

http://www.bbc.co.uk/news/technology-12325139

    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation
4 People had
this question

Was this helpful?

Answer

See...

Microsoft Security Advisory (2501696): Vulnerability in MHTML Could Allow Information Disclosure
http://www.microsoft.com/technet/security/advisory/2501696.mspx

NB: You will want to have a thorough read of the "Mitigating Factors and Suggested Actions" section on the above page.

NB: If you decide to run Fix It 50602 in KB2501696, you will need to run Fix It 50603 before you'll be able to install the patch for this vulnerability when it's released by Microsoft. In fact, the computer won't be offered the patch if Fix It 50603 hasn't been run.

 


~Robear Dyer (PA Bear) ~ MS MVP (IE, Mail, Security, Windows & Update Services) since 2002 ~ Disclaimer: MS MVPs neither represent nor work for Microsoft
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

PA Bear MS MVP

~Robear Dyer (PA Bear)
MS MVP-Windows Client (IE, Mail, Security & Update Services) since 2002

Was this helpful?

Answer

I have received this information on Facebook ..... is it accurate, or is it SPAM? I am new to this so not sure how to recognise authentic Microsoft information.

Don't want to download something I shouldn't !! I am not sure what IE version mine is.

And while it has not been able to remove the bug itself, it issued a "fix it" security patch to block any attempts to use it.

All Windows users - particularly those who use Internet Explorer - are being urged to download the fix while the company's security team develop a way to plug the hole permanently.

http://www.bbc.co.uk/news/technology-12325139

Yes, that's accurate. You should download the fix here: http://support.microsoft.com/kb/2501696

teengeek.freehostingcloud.com Microsoft Community Contributor
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Teen geek

Community Moderator
Teen  geek
Microsoft Comunity Contributor

Was this helpful?

Answer

I have received this information on Facebook ..... is it accurate, or is it SPAM? I am new to this so not sure how to recognise authentic Microsoft information.

Don't want to download something I shouldn't !! I am not sure what IE version mine is.

And while it has not been able to remove the bug itself, it issued a "fix it" security patch to block any attempts to use it.

All Windows users - particularly those who use Internet Explorer - are being urged to download the fix while the company's security team develop a way to plug the hole permanently.

http://www.bbc.co.uk/news/technology-12325139

Yes, that's accurate. You should download the fix here: http://support.microsoft.com/kb/2501696

teengeek.freehostingcloud.com Microsoft Community Contributor
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Teen geek

Community Moderator
Teen  geek
Microsoft Comunity Contributor

Was this helpful?

1

Vote

Is this not being released via Windows Update rather than expecting consumers to spot the issue and manually apply the fix it? There seems to be some scenarios where it should be applied and some where it shouldn't.

 


All answers and suggestions are provided by an enthusiastic amateur and are therefore without warranty either explicit or implicit. Basically you use my suggestions at your own risk.
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Jetta48

Community Moderator
Disclaimer: You use my posts entirely at your own risk. I do not work for or represent Microsoft.

Was this helpful?

I have exactly the same question - it isn't at all clear from the BBC news item and my update history doesn't appear to have anything in it. 
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

Answer

See...

Microsoft Security Advisory (2501696): Vulnerability in MHTML Could Allow Information Disclosure
http://www.microsoft.com/technet/security/advisory/2501696.mspx

NB: You will want to have a thorough read of the "Mitigating Factors and Suggested Actions" section on the above page.

NB: If you decide to run Fix It 50602 in KB2501696, you will need to run Fix It 50603 before you'll be able to install the patch for this vulnerability when it's released by Microsoft. In fact, the computer won't be offered the patch if Fix It 50603 hasn't been run.

 


~Robear Dyer (PA Bear) ~ MS MVP (IE, Mail, Security, Windows & Update Services) since 2002 ~ Disclaimer: MS MVPs neither represent nor work for Microsoft
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

PA Bear MS MVP

~Robear Dyer (PA Bear)
MS MVP-Windows Client (IE, Mail, Security & Update Services) since 2002

Message marked as answers cannot be deleted

To delete this message, first unmark this message as an answer, then delete it.

Reason to remove escalation


Merge

Enter the thread ID of the thread you are merging into


Reply will be posted to a public thread

You are replying to a public portion of this thread. To reply privately, click Cancel, click the Private Messages tab, and Reply on that private message.

Don't show this message again

To report abuse, sign in or continue without signing in

Thank you.

Report abuse

Abuse type:

Details (optional):

Report abuse

Abuse type:

Details (required):
Enter the characters you see (required):
Type the numbers that you see in the picture.
Play audio and type the numbers that you hear.
Show a different picture.

Sign in

Hotmail, Xbox Live, Messenger, or msn accounts will also work.

Don't have one of the above accounts?

Signing in...
This page will automatically update after you are signed in.
If you are having problems, you can close this message and try to connect again.