Saturday February 11, 2012 9:51 AM AEST

Microsoft updates on an IE vulnerability

By The Inquirer
10:27 Mar 3, 2010 | 8 Comments
Tags: Microsoft | updates | on | an | IE | vulnerability
Microsoft updates on an IE vulnerability

Microsoft recommends you tape over your F1 key.

Software house Microsoft has updated users of its Internet Explorer browser concerned about its latest vulnerability, and the advice is remarkably simple.

Yesterday in a security note the firm explained, "With this issue, it is possible for a malicious web page to display a dialog box which will trigger the execution of arbitrary code when the user presses the F1 key. The prompt can appear repeatedly when dismissed, nagging the user to press the F1 key. Platforms are affected regardless of the Internet Explorer version installed."

It added, "Though user interaction is required the F1 keyboard shortcut does enable an attack scenario. In the exploit, a file path enables a .HLP file to be loaded from the local filesystem, SMB, or WebDav."

According to the firm the problem relates to Windows 2000 and Windows XP by default, and to a lesser extent, Windows 2003 Server. It added that its internal investigations revealed that Windows 7, Windows Server 2008, and Windows Vista were not affected. Regardless of this, it appears that if there is a risk to systems it is users that cannot stop themselves from pressing a button.

Microsoft's workaround for the issue is uninspiring. It says, "As an interim workaround, users are advised to avoid pressing F1 on dialogs presented from web pages or other Internet content. If a dialog box appears repeatedly in an attempt to convince the user to press F1, users may log off the system or use Task Manager to kill the Internet Explorer process." So, no matter how hard they force you, and how tempting the prompt message is, just DO NOT PRESS THE F1 button. Oh, unless you actually need to.

There are other solutions, which are a bit more involved, for example, users can set IE to show them a prompt before running any "ActiveX" controls or scripting, and Microsoft added that this would not affect general browsing.

In the meantime, do not press the F1 button.

 

 

theinquirer.net (c) 2010 Incisive Media

 
Behind the scenes with Mass Effect 3! GTX 560 VGA round-up! Essential Skyrim tweaks to improve your game! Plus reviews, news, hardware, more games, and easy to following modding guides for PC builders. ON SALE NOW!
8 Comments
cyb3rspy
Mar 3, 2010 11:05 AM
mmm I'm not to sure on this I'm gonna need some help. :-)
sirtrancealot
Mar 3, 2010 1:47 PM
next microsoft "workaround" will be to leave your machine switched off at the wall.. just in case..
DishD
Mar 3, 2010 4:36 PM
Yet another reason to never, ever, use explorer, go firfox for the win! :[}
DishD
Mar 3, 2010 4:37 PM
firefox* grr
Tezlin
Mar 3, 2010 6:17 PM
Wait....people actually use IE? D:
Ezekill
Mar 3, 2010 6:28 PM
Luckily I don't use IE (pffft) or the F1 key.
neubejiita
Mar 3, 2010 7:47 PM
Internet Explorer can be uninstalled in XP with XPlite, but that removes ActiveX. Now I just run Ubuntu Karmic/Firefox.
thesorehead
Mar 4, 2010 10:00 AM
FF FTW
Comments have been disabled on this article.
 
Latest Competitions
 
Atomic Magazine

Issue: 133 | February, 2012

Atomic is a magazine aimed squarely at computer enthusiasts, gamers, and serious PC upgraders.

Every month we bring you the latest reviews of new technology and PC components, in depth features on everything from overclocking to console hacking, and gaming previews and interviews.
 
Latest Comments
 
Latest User Reviews
Battlefield 3 is the new benchmark online FPS
90%
A very fun and realistic multiplayer ride.
 
Antec Kuhler 920 - liquid cool
90%
Antec Kuhler 920 silent but effientive out of the box no maintence water cooling kit
 
Antec's Lanboy Air - our new favourite case
90%
Antec Lan boy Air in red a very cool design
 
Antec's Lanboy Air - our new favourite case
90%
This product overall is awesome.
 
MSI's GT780 laptop as fast as it gets
90%
Nice laptop
 
 
Close Get the February, 2012 issue of Atomic mailed to you for $8.95, including postage.

Buy nowDigital Version