Veteran bug hunter Georgi Guninski is recommending disabling Active Scripting - or ditching Internet Explorer entirely - after he discovered yet another vulnerability with the browser.
IE allows hackers to browse known local files using a specially crafted script due to a bug in the browser's GetObject() JScript function, Guninski reports.
The vulnerability, which is similar to previous directory transversal bugs and relates to how GetObject() interacts with the "htmlfile" ActiveX object, could allow the execution of arbitrary code on a target machine. Internet Explorer version 5.5 and 6.0 are thought to be affected.
|