Security Flaw Leaves All Microsoft Internet Explorer Users Vulnerable

CYBERSPACE — A new security hole affects all versions of Microsoft's Internet Explorer, leaving users of the leading web browser vulnerable to attack on a wide array of compromised websites.

Two online security firms have reported that hackers have broken in an unspecified number of websites and added malicious code that exploits the vulnerability in MS IE. Once installed, the virus starts stealing sensitive user data.

Online security firms Security Fix and SANS Internet Storm Center both reported on the vulnerability, which is linked to a specific file associated with MS IE. Microsoft also released an advisory, saying that the vulnerability is present in all versions of MS IE from version 5 onward.

But Washington Post tech security writer Brian Krebs noticed that some of the safety precautions recommended by Microsoft don't work quite right.

"Microsoft recommends enabling a feature called 'data execution prevention,' by clicking 'Tools,' 'Internet Options,' then 'Advanced,' and then checking the box next to that option," he said. "However, when I tried to make the changes in IE7 on Vista, I found that option grayed out. To make that change, I had to close out of IE completely, then right click on the IE icon, select 'Run as Administrator,' and then alter the setting."

Krebs also noted that Microsoft advised MS IE users to change their security setting to "high," even though such a setting renders most common websites unreadable. In addition, MS IE users can disable a specific function to prevent the attacks. The function is called "oledb32.dll." Unfortunately, Krebs also ran into trouble when trying to remove it, leading him to make a dramatic recommendation.

"I would advise Windows users to consider browsing the web with anything other than Internet Explorer, at least until Microsoft issues a patch to fix this vulnerability," he said. "It is not my intention to over-hype the situation, but as we have seen time and again, attackers are usually very quick to take advantage of flaws in IE because the program is the default browser for close to 80 percent of the planet."

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

FSC Publishes Analysis of Federal Trade Commission Event Promoting AV

Free Speech Coalition (FSC) has published an analysis of a Federal Trade Commission (FTC) event held this week that promoted age verification among other forms of speech regulation.

GirlsDoPorn Owner Michael Pratt Pleads Guilty to Sex Trafficking

Michael Pratt, former owner of the rogue website GirlsDoPorn, pleaded guilty in the U.S. District Court for the Southern District of California on Thursday to sex trafficking and conspiracy to commit sex trafficking charges, according to a report by City News Service.

Master Nico Relaunches Site Through YourPaysitePartner

Master Nico has relaunched his official website through YourPaysitePartner (YPP).

Federal Judge Grants Partial Halt of Florida AV Law

The United States District Court for the Northern District of Florida, Tallahassee Division, has granted a preliminary injunction against HB 3, the state's age verification law, as a lawsuit filed by two online trade associations challenging the law makes its way through the courts.

Aylo Releases Statement on Suspending Access to Pornhub in France

Technology and media company Aylo, which operates adult sites including Pornhub, YouPorn, and Redtube, has released a public statement regarding its decision to block access to its sites in France.

Pineapple Support to Host Wellness Sessions at Bucharest Summit

Pineapple Support is hosting free group and one-on-one therapy sessions at Bucharest Summit, June 3-5.

Pornhub Blocks Access in France in Response to SREN Law

Pornhub parent company Aylo has opted to block access to its sites in France rather than comply with age verification requirements under the country’s Security and Regulation of the Digital Space (SREN) law.

ASACP Highlights Study on Parental Controls

The Association of Sites Advocating Child Protection (ASACP) is highlighting the results of a study on the underutilization of parental controls.

Sydney Screams Launches New Site Through Grooby's Blue.xxx

Sydney Screams has launched her new membership site, SydneyScreams.xxx, through Grooby's website management company Blue.xxx.

Mistress Mystii Is LoyalFans' 'Featured Creator' for June

LoyalFans has named Mistress Mystii as its Featured Creator for June.

Show More