Secunia claims second IE 7 flaw

Secunia has reported a second flaw in Microsoft's Internet Explorer 7 browser

Just one week after claiming that users of Microsoft's Internet Explorer 7 browser could be at risk to an online attack, Danish security vendor Secunia is reporting a new bug in the browser.

The bug allows hackers to place a fake web address in one of the browser's pop-up Windows, and could be used to trick a victim into inadvertently downloading something from what appeared to be a trusted Web site. Secunia has described the flaw in an advisory, which can be found here.

Based on its initial investigation, Microsoft believes that there is "an issue," a spokesman with the company's public relations agency said in an e-mail.

While the full URL of the web page being displayed is present in the pop-up Window's address bar, the left part of this URL is not initially displayed, the spokesman said.

That problem could allow an attacker to spoof a legitimate website, Secunia said.

Microsoft's confirmation may come as a relief to Secunia which reported another problem in IE 7, just hours after the browser was released. Microsoft said Secunia's report was "technically inaccurate," however, because the flaw lay in a component of Microsoft's Outlook Express e-mail client, which could be triggered by the browser. Microsoft's comment on this issue can be found here.

Neither of the bugs is considered to be particularly critical. But coming so soon after IE 7's launch, they are somewhat of an embarrassment to Microsoft, which has made much of its focus on delivering secure software.

Secunia was surprised that Microsoft called their first report erroneous, given that the flaw can only be triggered through the browser, said Thomas Kristensen, Secunia's chief technology officer. "From a technical point of view, Microsoft might be right, but from a user's point of view, or an administrator's point of view, it doesn't really matter. IE is the vector," he said. "It was probably unnecessary to go out and try to blame Outlook in that way."

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Robert McMillan

IDG News Service
Show Comments

Essentials

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?