Windows 7 Forums


Windows 7: March Patch Tuesday didn't address MHTML vulnerability

16 Mar 2011   #1

Windows 7 Home Premium 32 bit
In a house with a cat trying to kill me
 
 
March Patch Tuesday didn't address MHTML vulnerability

Another fix to keep your eyes open for....

Quote:
Microsoft patched four vulnerabilities in this month's Patch Tuesday release, but unfortunately one that wasn't addressed was the MHTML issue in Windows and Internet Explorer - although a workaround was explained in a January security advisory.

Microsoft's March Security Update Doesn't Address MHTML Flaw -- Redmond Developer News

This is bad news because a few days ago, it was discovered that attackers are now exploiting that vulnerability to execute a "drive-by" browser attack by which they run Javascript on the user's computer to access information and/or force the download of more malware.

Report: Internet Explorer Used to Exploit Windows MHTML Vulnerability | News & Opinion | PCMag.com

Find the workarounds under the "Mitigating Factors and Suggested Actions" section here:

Microsoft Security Advisory (2501696): Vulnerability in MHTML Could Allow Information Disclosure
Edit...Thank you Hopalong X for this FixIt link:

http://support.microsoft.com/kb/2501696#FixItForMe

Quote:
The actual flaw is with the MHTML protocol handler in Windows--not in Internet Explorer itself--and affects all versions of the Windows operating system. However, Internet Explorer is the only known attack vector for exploiting the vulnerability.

Attacks exploiting this flaw are similar to cross-site scripting attacks and enable the attacker to intercept and collect user information, spoof the content that is displayed to the browser, or interfere with the user's browsing experience in other ways. It is also possible that the attacker may be able to run malicious scripts within the context of the IE session.



Last edited by Borg 386; 17 Mar 2011 at 04:35 PM..
My System SpecsSystem Spec

Reply

 March Patch Tuesday didn't address MHTML vulnerability problems?



Thread Tools



Similar help and support threads for: March Patch Tuesday didn't address MHTML vulnerability
Thread Forum
Patch Tuesday Windows Updates & Activation
MHTML 0-Day Vulnerability Won't be Patched Tomorrow Security News
Zero day vulnerability found in Windows MHTML renderer Security News
Patch Tuesday - 6/9/10 Windows Updates & Activation
Next Patch Tuesday won't hit Windows 7 News


All times are GMT -5. The time now is 09:40 PM.


Seven Forums Android App Seven Forums IOS App Follow us on Facebook

Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32