IE users: Refrain from pressing the F1 key when prompted by a website.
According to US-CERT, this one's real.
http://www.us-cert.gov/current/
Microsoft Releases Security Advisory to Address VBScript Vulnerability
added March 2, 2010 at 08:36 am
By convincing a user to view a specially crafted HTML document (web page, HTML email, or email attachment) with Internet Explorer and to press the F1 key, an attacker could run arbitrary code with the privileges of the user running the application.
US-CERT encourages users and administrators to do the following to help mitigate the risks:
- Review Microsoft Security Advisory 981169.
- Review the Microsoft Security Research & Defense blog entry regarding this issue.
- Review US-CERT Vulnerability Note VU#612021.
- Refrain from pressing the F1 key when prompted by a website.
- Restrict access to the Windows Help System.
US-CERT will provide additional information as it becomes available.
=====
US-CERT: United States Computer Emergency Readiness Team
US-CERT is charged with providing response support and defense against cyber attacks for the Federal Civil Executive Branch (.gov) and information sharing and collaboration with state and local government, industry and international partners.
Your E-mail and More On-the-Go. Get Windows Live Hotmail Free. Sign up now.
0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home