ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Become a ZDNet.co.uk member

Resources Downloads

Download Now

eEye patch for the IE createTextRange() vulnerability


License Free
Requirements Windows 98/Me/NT/2000/XP/2003 Server, Internet Explorer 5.01 or 6.0
Downloads 38 Limitations None
Publisher eEye Digital Security File Size 936k
Date added 29 Mar 2006 Check your speed

Note:Organizations should only install this patch if they are not able to disable Active Scripting as a means of mitigation.

eEye Digital Security is advising customers to the existence of exploit code that targets a critical security vulnerability in Microsoft Internet Explorer. The exploit pertains to an unpatched vulnerability that has been released on various public mailing lists.

This issue affects any Windows operating system running Internet Explorer versions 5.01 SP4 through 6.0 SP1. The vulnerability results from the method in which Internet Explorer handles HTML Objects. This flaw allows for remote code to be executed on the target system. If successfully exploited, an attacker will only have the rights of the currently logged on user. System Administrators should be careful to not use Administrator accounts for general system use.

There have been numerous reports of this vulnerability being used on various websites in attempts to install Spyware and remote control ""bot"" software for use in Distributed Denial of Service (DDoS) attacks.

The recommended action required to protect systems against this attack is to disable Active Scripting from within Internet Explorer.

Additionally, eEye Digital Security s Research Team has released a workaround for the vulnerability as a temporary measure for customers who have not yet installed Blink, eEye's host-based intrusion prevention solution. This workaround is not meant to replace the forthcoming Microsoft patch, rather it is intended as a temporary protection against this flaw.

Download Now

Did you find this download useful?
25 out of 50 users found this download useful




Download

Embarcadero Power SQL

Embarcadero PowerSQL simplifies SQL development for application developers with many features for improving productivity and reducing errors.

  • Downloads: 1,875
  • Requirements:
  • License: Vendor registration required
  • Publisher: Embarcadero
  • Size: 0

Download Now

Featured Talkback

Why do so many (virtually all) software packages think that they are so important that they have to be started automatically every time the computer boots? What is the largest number of "speed access", "update check", "camera download" and whatever other background programs you have ever seen running? Of those, how many did you really need?

By: J.A. Watson

Read full story:
Annoying software: a rogues' gallery

Discussions

roger andre roger andre

Beware Of Sneaky Services

Sunday 6 July 2008, 1:27 AM

7 comments
Moley Moley

It might be nice

Saturday 5 July 2008, 8:24 PM

1 comment

Vista Upgrade Blog

XP survival, from one horses mouth, an...

Hi everyone....for those that need more information on XP survival, I have pasted this open letter from Bill Veghte, senior vice president of microsoft, found on microsoft .com. Hope... More

2 comments

A $40 CONSUMER-class router has create...

Believe it or not I don't work in IT, haven't for 7 years. Yes I work with Microsoft's Windows XP Embedded and as a result I have to know a lot about the OS, the kernal, Win API calls... More

Post a comment

Sick Puppy Redo

I generally follow a dispassionate investigative process when trying to discern what happened when a project goes bad. Although its a low priority item, it gets done simply because... More

Post a comment