‘Extremely critical’ Windows flaw - caused by IE (for a change!)
Wednesday, November 23rd, 2005Another cracker brought to you by Microsoft – a screwup in the way IE understands ‘body onload’ statements (not put them in chevrons as it would be interpreted as HTML) can give a remote attacker complete control over a system – with the same privileges as the user currently logged on (which means full access on XP as limited users can’t even change the damn clock). I repeat what I said a few days ago – if IE wasn’t in Windows (or wasn’t hooked into Windows Explorer the way it is now) it would be a much more secure operating system. The flaw is rated ‘extremely critical’ by Secunia.