Security flaw in Internet Explorer still not fixed
Last Updated: Tuesday, December 16, 2008 | 8:30 AM ET
The Associated Press
Related
Internal Links
Video
- CBC's Heather Hiscox interviews technology expert Jesse Hirsh (Runs: 4:08)
- Play: QuickTime »
- Play: Real Media »
External Links
(Note: CBC does not endorse and is not responsible for the content of external sites - links will open in new window)
Users of all current versions of Microsoft Corp.'s Internet Explorer browser might be vulnerable to having their computers hijacked because of a serious security hole in the software that had yet to be fixed Monday.
The flaw lets criminals commandeer victims' machines merely by tricking them into visiting web sites tainted with malicious programming code. As many as 10,000 sites have been compromised since last week to exploit the browser flaw, according to antivirus software maker Trend Micro Inc.
The sites are mostly Chinese and have been serving up programs that steal passwords for computer games, which can be sold for money on the black market. However, the hole is such that it could be "adopted by more financially motivated criminals for more serious mayhem — that's a big fear right now," Paul Ferguson, a Trend Micro security researcher, said Monday.
"Zero-day" vulnerabilities like this are security holes that haven't been repaired by the software makers. They're a gold mine for criminals because users have few ways to fight off attacks.
The latest vulnerability is noteworthy because Internet Explorer is the default browser for most of the world's computers. Also, while Microsoft says it has detected attacks only against Version 7 of Internet Explorer, which is the most widely used edition, the company warned that other versions are also potentially vulnerable.
Microsoft said it is investigating the flaw and is considering fixing it through an emergency software patch outside of its normal monthly updates, but declined further comment. The company is telling users to employ a series of complicated workarounds to minimize the threat.
Many security experts, meanwhile, are urging Internet Explorer users to use another browser until a patch is released.
Share Tools
Top News Headlines
- Greece passes new austerity deal amid rioting
- Greek lawmakers have approved harsh new austerity measures demanded by bailout creditors to save the debt-crippled nation from bankruptcy, after riots in Athens and other cities left stores looted and burned and more than 120 people hurt. more »
- Quebec town 'heartbroken' after killing of woman, sisters
- A small Quebec town is in mourning Sunday after a Quebec man was charged with killing his nieces and his mother, who were found dead in their family home. more »
- Houston autopsy results withheld by police
- Whitney Houston was found in a hotel bathtub but it'll take weeks to determine precisely how she died, a Los Angeles coroner's official says. more »
- Musicians who died before their time
- The growing list of musicians who have died young. more »
Latest Technology & Science News Headlines
- Ancient Antarctic lake may harbour microbial life
- If scientists find microbes in a frigid lake 3.2 kilometres beneath the thick ice of Antarctica, it will illustrate once again that somehow life finds a way to survive in the strangest and harshest places, and it will offer hope that life exists beyond Earth. more »
- B.C. killer whale habitat protection ruled a legal duty
- The federal minister of fisheries has no discretion when it comes to protecting the critical habitat of B.C.'s southern resident killer whales, the Federal Court of Appeal has ruled. more »
- Game developer seeks $400K, makes $1M in a day
- Videogame studio Double Fine went on the website Kickstarter to raise $400K US in a month to develop a new game. They reached that target in a matter of hours. more »
- McGill asbestos study review criticized
- A group of anti-asbestos activists and scientists are criticizing McGill University's plans for an internal review of a major asbestos research study that has been called into question. more »
Bob McDonald's Blog
Glacier Discovery Walk: Will the visitor centre enhance the view? Feb. 10, 2012 3:17 PM Environment minister Peter Kent has announced the construction of a new Glacier Discovery Walk and visitor centre on the Icefields Parkway in Jasper National Park. It raises the issue of how to balance commercial development in our National Parks against the preservation of the last refuges of wilderness.
Quirks & Quarks
- February 11: Inside the Mind of a Neandertal Feb. 10, 2012 4:01 PM Can we get inside the mind of a species that's been dead for 30,000 years? A new book, How to Think Like a Neanderthal, suggests we can. The authors reconstruct a creature like us in many ways, but with important differences.
Latest Features
- Pop queen Whitney Houston dies at 48
- Houston autopsy results withheld by police
- Greece passes new austerity deal amid rioting
- Carleton University confirms death of student
- Adele takes 4 Grammys
- Quebec town 'heartbroken' after killing of woman, sisters
- Ultimate Tazer Ball combines shock and soccer
- Manitoba man dies after falling off moving SUV
- Adults-only trade show cancelled in B.C. Bible belt

