The Channel logo


By | John Leyden 28th March 2006 13:34

eEye issues workaround against unpatched IE flaw


Security firm eEye Digital Security has released a temporary fix to protect Windows users against an unpatched vulnerability in Internet Explorer.

The critical vulnerability, which involves the way IE handles HTML Objects, affects even fully patched Windows XP systems. Exploits allow hackers to commandeer vulnerable machines by tricking surfers into visiting websites containing malicious code.

Users are advised to disable Active Scripting from within Internet Explorer as a workaround pending the arrival of a patch from Microsoft, expected on Tuesday, 11 April. Disabling Active Scripting might prove problematic in some environments, however, so eEye has stepped in to fill the breach with a temporary workaround.

"Users can protect themselves by manually making configuration changes, but eEye realises that not all organisations can take those steps. As a result, organisations should only install this patch if they are not able to disable Active Scripting as a means of mitigation," eEye cofounder and chief hacking officer Marc Maiffret said.

eEye stresses that its workaround shouldn't be seen as a substitute for a fully tested patch, but will provide "immediate protection in lieu of an available fix". In fact, eEye has engineered the patch to automatically remove itself when Microsoft's official patch comes through," Maiffret added. ®

alert Send corrections


Frank Jennings

What do you do? Use manual typwriters or live in a Scottish croft? Our man advises
A rusty petrol pump at an abandoned gas station. Pic by Silvia B. Jakiello via shutterstock

Trevor Pott

Among other things, Active Directory needs an overhaul
Baby looks taken aback/shocked/affronted. Photo by Shutterstock

Kat Hall

Plans for 2 million FTTP connections in next four years 'not enough'
Microsoft CEO Satya Nadella


League of gentlemen poster - Tubbs and Edward at the local shop. Copyright BBC
One reselling man tells his tale of woe