Microsoft Internet Explorer 7 plays catch up, sees first exploit less than 24 hours after release

“Microsoft has made Internet Explorer 7 (IE 7) available to the general public,” BBC News reports. “The new version is the first upgrade to the web browsing program for more than five years.”

“New features include tabbed browsing, the ability to search the net directly and an anti-fraud system to thwart phishing attacks,” The Beeb reports. “The new program is available as a free download on 19 October, but many will get it as an automatic update to Windows XP in November.”

Microsoft’s Internet Explorer 7 is “seen as an attempt by Microsoft to catch up with rival browsers as it includes features that have long been seen in competitors such as Firefox and Opera,” The Beeb reports.

MacDailyNews Note: And Apple’s Safari which, of course, The Beeb ignores.

The Beeb continues, “With the new version, it is possible to open up tabs rather than windows for new webpages and subscribe to RSS feeds via the browser. One controversial new feature is the addition of a box that lets people search the net directly from the browser rather than through a dedicated webpage. This defaults to Microsoft’s own search engine, but in a last minute change the software company is letting users choose which search site this feature should call upon.”

“IE 7 will also be the default browser for the next version of Microsoft Windows, known as Vista, that is due to be launched in 2007,” The Beeb reports.

Full article here.

Les than 24 hours after release, a vulnerability has already been discovered in Microsoft Internet Explorer 7.x, “which can be exploited by malicious people to disclose potentially sensitive information,” Secunia reports. “The vulnerability is caused due to an error in the handling of redirections for URLs with the “mhtml:” URI handler. This can be exploited to access documents served from another web site.”

Secunia has confirmed the vulnerability on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2 and says ther versions may also be affected.

Secunia advises users to “disable active scripting support.”

Secunia Advisory here.

44 Comments

  1. The primary reason WHY Microsoft is UNABLE to eradicate their ongoing security issues with the Windows NT/2000/XP operating system codebase is due to a fundamentally FLAWED Windows OS security model/architecture.

    The ONLY way to fix the problem would be to rip out most of the old Windows OS codebase and REWRITE/REARCHITECT to modern security model standards. Unfortunately for MS, IF they were to perform this level of radical surgery upon the Window OS, they would immediately create a nightmare for the custom/third party application/utility software industry, and particularly custom in-house corporate software applications that would no longer work, and would require a SIGNIFICANT expenditure of third-party dollars, time and resources to correct.

    MS owns the corporate desktop market, and the corporate desktop market owns MS — neither can afford sudden radical changes in their IT environments, and each lock the other into a very slow, incremental approach to product changes.

  2. People you can always move to Linux or Macs.
    Since the OS is not based on Unix by Microsoft. Its build on DLL. Lets see How Vista Does in January 2007 with sucurity. As it says it more secure but not 100%. Because it asks for Permissions by annoying dialog boxes in vista. Which you can turn off in control panel under user account Turn user Account on or Off. Just dont use stuff under Administrar Account. Create a another account to do stuff.

    Hint: if windows users having another issue another then this exploit like in IE7 from some sites not working in SSL HTTPS. turn off TLS 1.0 by unchecking the box its on by Default in Internet Options under advanced options ok. Then the Problem will be solved. All sites in SSL HTTPS will work fine. Bye

  3. niff stipples –

    I digress. You are right on.

    It still puzzles me how MS and these 3rd party people can’t fix their own messes. All it takes is some brain power, no? I still can’t help but to think that many security problems are intentional…there are so many!

  4. IE7 hacking?? Impossible. I tell you its impossible. Remember all those that said the Mac had no viruses because of its obsecurity?? Will then, there can be NO viruses for IE7 since its just released and almost no one has it. There for, did not happen.

    did not happen! ” width=”19″ height=”19″ alt=”grin” style=”border:0;” />

    Nope. !!

    Everything is good. ” width=”19″ height=”19″ alt=”grin” style=”border:0;” />

    N. ” width=”19″ height=”19″ alt=”grin” style=”border:0;” />

  5. I just downloaded it on my PC to give it a spin.

    File error, cannot connect to the Internet!!!!

    Internet Explorer cannot display the webpage

    Most likely causes:
    You are not connected to the Internet.
    The website is encountering problems.
    There might be a typing error in the address.

    What you can try:
    Diagnose Connection Problems

    More information

    This problem can be caused by a variety of issues, including:

    Internet connectivity has been lost.
    The website is temporarily unavailable.
    The Domain Name Server (DNS) is not reachable.
    The Domain Name Server (DNS) does not have a listing for the website’s domain.
    If this is an HTTPS (secure) address, click Tools, click Internet Options, click Advanced, and check to be sure the SSL and TLS protocols are enabled under the security section.

    For offline users

    You can still view subscribed feeds and some recently viewed webpages.
    To view subscribed feeds

    Click the Favorites Center button , click Feeds, and then click the feed you want to view.

    To view recently visited webpages (might not work on all pages)

    Click Tools , and then click Work Offline.
    Click the Favorites Center button , click History, and then click the page you want to view.

    I couldn’t make this up if I tried!

    Of course I’m typing this on my broswers that do connect to the internet.

  6. In IE7 some sites will not work in SSL HTTPS. Turn off TLS 1.0 by unchecking the box its On by Default in Internet Options under advanced options. Then the Problem will be solved. All sites in SSL HTTPS will work fine. It has for me solved the issue. Unless your having an issue with ISP. Bye

  7. anyone see anything wrong with this (from ms website ie 7….

    Q. Why can’t I see the File menu in Internet Explorer 7?
    A.To maximize website viewing, the File menu is hidden by default. Most menu options can be accessed from the toolbar. To view the File menu simply click on the ALT key.

  8. Right Click close to Home Sign in IE7 then you see options like Menu Bar, Links, Status Bar and select Menu Bar. Then File Edit View Favorites Tools Help will come on top of tabs ok Permanently. Bye take care.

  9. Vista Rc2 is a Memory Eater. Its at 835Mb memory usage after 7 days uptime. It was at 435 the first day when idle. Thats why some sites say if you need to be at safe side get 1Gb or 2Gb with Vista. The word when pc manufacturers say vista capable with 512Mb. Are they out of there Minds. With 512Mb people will have Problems. More memory the better it will Perform. I suggest at Least 1Gb ram. Bye

  10. I don’t get it. Microsoft slams Apple because a miniscule number of iPods are infected by a Windows-only virus from Windows-only machines, but there’s not a peep from the Beeb about Microsoft’s malware magnet, IE, that attracts in digital badness from every corner of the globe and is now available for tens of millions of PCs. And this after “five years” of development of IE 7.

Reader Feedback

This site uses Akismet to reduce spam. Learn how your comment data is processed.