
Microsoft IE vulnerability is caused due to an error in the processing of the "createTextRange()" method call applied on a radio button control. A radio button is a form field that presents the user with a selection that can be chosen by clicking on a button.
"Microsoft has determined that an attacker who exploits this vulnerability would have no way to force users to visit a malicious Web site . Instead, an attacker would have to persuade them to visit the Web site, typically by getting them to click a link that takes them to the attacker's Web site," Microsoft said in its Security Advisory.
The unpatched CreateTextRange vulnerability in Microsoft Internet Explorer is already being used by at least one Web site to install spyware on users' machines, a security organization said Friday.
Send to a friend | Permalink | Del.icio.us | Go To Top
Translate:




