Two new security flaws have been discovered in Microsoft's Internet Explorer, one of which could be replicated in Mozilla's Firefox, security experts have warned.

Code for both of the vulnerabilities has been published, but currently there are no reports of attackers who have taken advantage of these flaws, the SANS Internet Storm Center, which monitors network threats, said in an advisory released Wednesday.

The flaw that affects both IE and Firefox is related to the handling of the object.documentElement.outerHTML property, according to the advisory. That technology is used to access documents delivered from one Web site to another.

Attackers could exploit the IE or Firefox flaw using what's known as cross-site scripting, allowing them to view the contents of one open browser from a second browser open on the user's system, said Monty Ijzerman, senior manager of McAfee's Global Threat Group. The attackers, as a result, could swipe sensitive information, such as online banking data, from one of the sites, for example.

"We consider this flaw less serious than the other IE flaw," Ijzerman said. "A user would have to have multiple browsers open, and the information on the site would have to be relevant to what the attacker wanted."

The second flaw is related to the way HTA applications are processed. A user could be tricked into double-clicking on a malicious file and remote code could be executed, Ijzerman said. An attacker could exploit the vulnerability to read files on a system or install rootkits, which make system changes to hide another piece of possibly malicious software.

The two IE security flaws come as Microsoft releases its final beta version of IE 7, which is designed to offer more security features.

Microsoft said it is investigating the issue and has yet to hear of any attackers exploiting the reported vulnerabilities.

Mozilla was not immediately available for comment.

Like this article? Click below to send it to your mobile for free!

Be the first to comment on this article!

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • 50 significant moments from internet history

  • Skyfire mobile browser bulks up for open beta

  • Muxtape founder 'walked away from licensing deals'

  • 101 software tips, tweaks and tricks

  • Don't shoot Microsoft's new Messenger

  • Google offers cutting-edge Chrome, first update

  • New Opera beta sports email, feed changes

  • Google quietly updates Chrome

  • Chrome (beta)

More articles »

Find the right software

Brand
  • Multiple options can be selected

    • Chrome (beta)

      Chrome (beta)

      Google has rethought the Internet browser — some of its basic underpinnings are quite novel — but users will recognise some features as they exist in other, open-source browsers on the market today.

    • Internet Explorer 8 Beta 2

      Internet Explorer 8 Beta 2

      Microsoft's release should retain its browser base but doesn't yet have enough to lure loyal Firefox users back to Internet Explorer.

    • MobileMe

      MobileMe

      MobileMe is the successor to .Mac, Apple's subscription service for publishing photos and other personal content to the Web.

    • Firefox 3

      Firefox 3

      If only for the speed, lightness of being and security alone, Firefox remains our Editors' Choice for best internet browser.

    • Opera 9.5

      Opera 9.5

      Long considered a cult favourite, Opera 9.5 for Windows and Mac has introduced some compelling improvements to security, speed and synchronisation — yes, syncing in a browser!— is there enough here to make you a convert?

    More reviews »

    Membership benefits

    Create a personalised homepage

    Create a personalised homepage

    Choose your interests from our 16 categories and only see articles relevant to you. Sign up for a free CNET.com.au membership now!