Unpatched Vulnerability in IE 7
Posted in All Posts, General, Online Security, Privacy, Safe e-Commerce on November 3rd, 2006The security firm, Secunia has reported a vulnerability in Internet Explorer 7. The vulnerability is referred to as an “MHTML hole”. Basically, a malicious web site can fake you into disclosing sensitive information. Secunia describes it as follows:
Description:
A vulnerability has been discovered in Internet Explorer, which can be exploited by malicious people to disclose potentially sensitive information.The vulnerability is caused due to an error in the handling of redirections for URLs with the “MHTML:” URI handler. This can be exploited to access documents served from another web site.
For more information and a test for your browser, go to Secunia.com at the following address:
http://secunia.com/advisories/22477/
The cure, for the time being, until this is patched by Microsoft, is to turn off active scripting.

