Microsoft warns of 'F1' pop-up flaw
By Nicole Kobie,
Microsoft is looking into a new flaw that could let hackers run code if they can convince users to hit the 'F1' key in response to a pop-up window.
In a post on the Microsoft security blog, communications manager Jerry Bryant said that the flaw was made public on Friday, but that the company hadn't seen any attacks yet, and that computers running Windows 7, Vista or Sever 2008 are not affected - so XP users beware.
"The issue in question involves the use of VBScript and Windows Help files in Internet Explorer," Bryant noted.
"Windows Help files are included in a long list of what we refer to as 'unsafe file types'," he explained. "These are file types that are designed to invoke automatic actions during normal use of the files. While they can be very valuable productivity tools, they can also be used by attackers to try and compromise a system."
Microsoft said it will "take appropriate action" once it had finished examining the flaw, and advised users to make sure their anti-virus and software was up-to-date.
Bryant also called for such flaws to be reported to vendors like itself, instead of made generally public. "To minimise risk to computer users, Microsoft continues to encourage responsible disclosure," he said.
"Reporting vulnerabilities directly to vendors without further disclosure helps ensure that customers receive comprehensive, high-quality updates before cyber criminals learn of – and work to exploit – a vulnerability."
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
Do British police get cyber security?
Davey Winder listens to telephone conversations between the FBI and the Metropolitan Police, courtesy of Anonymous, and isn't impressed.
- Who to trust after the VeriSign hack?
- Striving to solve the security skills crisis
- Would you employ a hacker or malware writer?
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- Is there such a thing as a secure tablet?
- 2011: The year in news
- BYOD: Old or new, good or bad?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Ubuntu vs. Windows 7 on the business desktop
- York researchers heat storage to speed up data
- BlackBerry Bold 9790 review
- OneNote hits Google?s Android
- O2 trials Olympic-scale remote working
- Will someone rid me of these troublesome Macs?
- Lenovo beats expectations again
- Who to trust after the VeriSign hack?
- Google to promise fairness after Motorola buy
- Report: Google cloud storage coming soon
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






Fun with MS & IE
So that would be "Don't use our own browser" then, would it?
By HappyJoe on Tuesday Mar 2