Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


February 18, 2004

Leaked Code Leads to Vulnerability Discovery in IE 5.x

RSS
Subscribe to Windows IT Pro | See More Internet Explorer (IE) Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Last week it became apparent that somehow the large portions of source code to Windows 2000 and Windows NT had become leaked onto the Internet. Some sources indicate that over 30,000 files of the Windows 2000 source code were part of that leak.

Speculation was raised as to whether the leak might lead to the discovery of new security vulnerabilities. As it turns out the first vulnerability has already been discovered and published to the public.

Someone with access to the code found a hole in Internet Explorer 5.x and on Monday the details were released where they wound up on various security mailing lists. Researchers have since confirmed the discovery as genuine and Microsoft also acknowledged its existence.

A spokesperson for Microsoft said that “This exploit is a known issue that [we] had discovered internally and addressed with the latest release of Internet Explorer -- Internet Explorer 6.0 Service Pack 1.”

The vulnerability report states that the problem is an integer overflow condition caused by a specially crafted bitmap file. When IE 5.x loads such a bitmap file an overflow is triggered that could allow arbitrary code to execute on an affected system. The person who released the vulnerability report also released a proof of concept bitmap file. The problem has been confirmed to at least cause a denial of service condition in IE 5.01 with Service Pack 1 and Service Pack 2 installed.

As you might suspect, Microsoft recommends that users upgrade to IE 6.0. However the company is reportedly working on a fix for IE 5.x versions of the browser.

End of Article



Reader Comments
This article is stupid hype. Who cares about a vulnerability in IE 5.01. This author is doing nothing more than jumping on the over-hype bandwagon- write a real articel.

Ward February 18, 2004


How could this happen and what does it mean. I've heard that a hacker can get all the information on the computer because of this. This is scary.

Faith Pewitt February 19, 2004


What should I do, if anything, to keep a hacker from getting information from my computer which is Windows XP?

Faith February 19, 2004


Very disturbing. I'd like to know how many other security vulnerabilities Microsoft has fixed in the past without letting the end users know about it.

James February 20, 2004


This is unbelievable. Less than a week after 30,000 files become available someone has managed to find a vulnerability already. How come Microsoft themselves can't find these problems when they have ALL the source code and THEY wrote it. It reaks of Microsoft beta testing their software on the paying public after it's released.

Sean Wilson February 26, 2004


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

How can I convert a SQL date/time to just date?

...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events The Increasing Threat of Financially Motivated Data Theft

Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement