SHARE
Facebook X Pinterest WhatsApp

Serious IE Hole Opens PCs Up to Attacks

US-CERT on Wednesday warned of a fresh hole in Internet Explorer that could allow attackers to take control of a PC via an HTML e-mail message or a malicious Web page. The flaw is all the more serious because exploit code has been published on public mailing lists, according to security researchers. The flaw, a […]

Nov 4, 2004
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

US-CERT on Wednesday warned of a fresh hole in Internet Explorer that could allow attackers to take control of a PC via an HTML e-mail message or a malicious Web page. The flaw is all the more serious because exploit code has been published on public mailing lists, according to security researchers.

The flaw, a heap buffer overflow, is in the way IE handles two attributes of the “frame” and “iframe” HTML elements. An exploit currently circulating uses overly long SRC and NAME attributes to cause IE to execute an attacker’s shell code, according to US-CERT.

Read here why Peter Coffee says IE flaws should come as no surprise.

Users could be attacked via a malicious Web page viewed in an affected version of IE or possibly through an HTML e-mail viewed in an application such as Outlook, Outlook Express, AOL or Lotus Notes that relies on the WebBrowser ActiveX control, according to researchers.

The bug has been confirmed in IE 6.0 on Windows XP with SP1 and all patches installed, as well as the same browser on a fully patched Windows 2000, according to an advisory from security firm Secunia. Microsoft Corp. has not yet released a patch.

Windows XP systems running Service Pack 2 do not appear to be affected, researchers said. Apart from installing SP2, system administrators can lessen the danger of an attack by disabling active scripting, avoiding unsolicited links that may lead to a malicious Web page and rendering e-mails in plain text, US-CERT said. Updated anti-virus programs may also be able to prevent some exploit attempts.

For insights on security coverage around the Web, check out eWEEK.com Security Center Editor Larry Seltzer’s Weblog.

The fact that fully patched SP1 systems are vulnerable to the flaw, while SP2 systems are not, appears to show that the work put into Microsoft’s security-oriented update is paying off. A spoofing flaw in IE publicized over the weekend also affects pre-SP2 systems but is largely disabled by the service pack.

Check out eWEEK.com’s for the latest security news, reviews and analysis.

Recommended for you...

Lightbeam Hires Former CrowdStrike Exec as New Channel Leader
XenTegra CTO Sellers on AI, Security & More 2026 Opportunities
November Leadership Recap: ‘Tis the Season for New Appointments
Jordan Smith
Dec 1, 2025
Nerdio Expands Capabilities in AVD & Microsoft Ecosystem
Victoria Durgin
Nov 28, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.