Yet another flaw hits IE browser
Another week, another hole is found in Internet Explorer.


Microsoft has admitted another vulnerability in older versions of its Internet Explorer browser, with attacks already taking advantage of the problem.
The flaw only affects IE6 and IE7, not IE8. Naturally, Microsoft has again advised users to upgrade to IE8.
The Microsoft bulletin said the flaw is linked to an invalid pointer reference. "It is possible under certain conditions for the invalid pointer to be accessed after an object is deleted. In a specially-crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution."
Microsoft said hackers are already making use of the flaw. "At this time, we are aware of targeted attacks seeking to exploit this vulnerability against Internet Explorer 6," communications head Jerry Bryant said on the Microsoft security blog.
The firm noted that the Internet Explorer Protected Mode in IE7 running on Vista helps to "mitigate" the problem, while instances of the browser running on Server 2003 and 2008 should also be safe because of default security settings.
Microsoft said it is still investigating the flaw, and will offer an update either through the monthly patching cycle - not due again until April - or an out-of-band patch.
Read on for more about the problems facing Internet Explorer.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published