Third flaw found in IE7

Secunia issues new alert as flaw number three is found in Microsoft's new browser

Microsoft's new browser Internet Explorer 7 (IE7) has had a third flaw identified barely a week after the code was released.

The flaw was identified over the weekend by researchers Per Gravgaard and allows a hacker to subvert legitimate web sites. By crafting special code a hacker can spoof legitimate online sites with their own web pages.

"The problem is that a website can inject content into another site's window if the target name of the window is known," warns the advisory.

"This can e.g. be exploited by a malicious website to spoof the content of a pop-up window opened on a trusted website."

The problem arises in the way the browser handles pop-up pages. Using the flaw a hacker could choose a legitimate pop-up URL and when it opened overlay new web copy in the window, which could be used to harvest the target's personal details.

IE7 should be able to defeat this kind of attack as it displays the current URL of any pop-up, unlike earlier versions of the browser. But, when used in conjunction with the second flaw found in the browser a combination attack can fool IE7 users.

The first security flaw in IE7 was found within days of its release, but Microsoft has disputed this, claiming the problem is not with IE7 but with other applications using the browser.

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now
Advertisement

Recommended

Visit/software/video-conferencing/355410/zoom-50-adds-256-bit-encryption-and-ui-refresh
video conferencing

Zoom 5.0 adds 256-bit encryption to address security concerns

23 Apr 2020
Visit/security/hacking/355382/whatsapps-flaw-shoulder-surfing
hacking

WhatsApp flaw leaves users open to 'shoulder surfing' attacks

21 Apr 2020
Visit/security/cyber-security/355368/microsoft-builds-ai-to-detect-security-flaws-with-99-accuracy
cyber security

Microsoft AI can detect security flaws with 99% accuracy

20 Apr 2020
Visit/security/vulnerability/355276/businesses-brace-for-second-fujiwhara-effect-of-2020-as-patch-tuesday
vulnerability

Businesses brace for second 'Fujiwhara effect' of 2020 as Patch Tuesday looms

9 Apr 2020

Most Popular

Visit/mobile/5g/355712/nokia-5g-speed-record
5G

Nokia breaks 5G record with speeds nearing 5Gbps

20 May 2020
Visit/cloud/cloud-computing/355742/microsoft-launches-public-cloud-service-for-health-care
cloud computing

Microsoft launches public cloud service for health care

21 May 2020
Visit/software/video-conferencing/355596/house-of-commons-to-ditch-zoom
video conferencing

House of Commons to ditch Zoom in favour of British alternative

11 May 2020