View Single Post
  #1  
Old 30th Jul 07, 07:34 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 31,898
NewsBot will become famous soon enough
IE7/Firefox URI Handling Bug Caused by Windows After All
*Source: BetaNews (http://www.betanews.com/article/IE7F...l/1185811085)*
______
An exploitable bug discovered earlier this month that was first believed to have been caused by Internet Explorer 7.0, before Mozilla was forced to admit that it afflicted Firefox as well (http://www.betanews.com/article/Mozi...IE/1185314034), has apparently been traced back to a Windows API function.

The discovery may have been first revealed through the US-CERT Web site of the Dept. of Homeland Security, which now classifies it as a "Microsoft Windows URI protocol handling vulnerability (http://www.kb.cert.org/vuls/id/403150)." The function in question is an old favorite of malware writers: ShellExecute(), which was the subject of a notorious Windows 2000 exploit (http://www.internetnews.com/dev-news...le.php/2231361) four years ago.

More...
Reply With Quote