Newsletter

Newsletter TechSpot Poll

Get weekly updates on new articles, news and contests in your mail!

Email address:

Security

IE flaw affects IE6, 7 and 8

By Justin Mann, TechSpot.com
Published: June 30, 2008, 5:55 PM EST
IE flaw affects IE6, 7 and 8

A warning for a recently discovered flaw in Internet Explorer 6 and 7 is being issued. The flaw is related to iframes, which most of us encounter in the form of ads of various sorts, and how IE6/IE7 handles access restriction on them. The attack requires at least some user intervention, but appears to be exploitable just by visiting a maliciously crafted web page or opening an e-mail.

The flaw is new enough that Microsoft says they aren't aware of anyone being compromised by the attack, even though proof of concept code has apparently been around for over a month. Interestingly, even Microsoft's newest browser, IE 8 beta 1, which was made available earlier this year, is also vulnerable.

Microsoft is now in an interesting position. Once IE8 becomes final and people begin adopting it, they'll be left with a very substantial userbase that is composed of IE6, IE7 and IE8 users. It seems they will be stuck with supporting the older browsers, and maintaining three branches of IE at once can't be an easy chore, even for Microsoft.

User Comments (1)

Post a comment
supergirl260
on June 30, 2008
7:05 PM
microsoft will support ie5.5 on windows 2000 untill 7/13/2010 for secuity updates only

Microsoft will support ie6 on windows xp until 4/8/2014 possibly later

microsoft will support ie7 on vista (business only) untill 4/11/2017

all dates are minimum and microsoft can extend support for longer if they choose

Browse more commented news

Post a new comment