With Exploit Out, Microsoft Rushes IE 7 Fix
Using Internet Explorer 7 on Windows XP PCs remains risky. Plus: Grab Microsoft's Office and mail fixes, and beware of PDF attachments.
Stuart J. Johnston, PC World

The problem lies in how IE 7 interacts, via its URI (uniform resource identifier) handler, with products such as Adobe's Acrobat Reader or Mozilla's Firefox. At first, Microsoft stonewalled, pointing a finger at Firefox; then, after acknowledging that the problem was its own, the company dragged its feet on a fix because no exploit existed. That changed when a PDF Trojan horse attack started making the rounds in October. Adobe patched Reader (see below), but that covers only one end of the worm hole.
Microsoft's patch has been in testing for a while and apparently will remain so for some time. My advice to Windows XP users: Stick with Firefox, version 2.0.0.6 and up, which already has a patch for the URI vulnerability. For more, read our updated information on the URI patch for IE 7.
PDF Joins the Risky List
The PDF attack that forced Microsoft's hand on the IE 7 fix described above also serves as a reminder: When it comes to unsolicited e-mail, trust no sender and no attachment, regardless of the file format.
The Trojan horse attack, which arrives in an infected Portable Document Format file, brings an old social-engineering ploy to PDFs, which malware filters usually don't vet. Carrying a subject line such as "invoice" or "bill", the tainted message's aim is to trick you into clicking. Don't.
Opening e-mail attachments is growing riskier. A Microsoft report found that the first half of 2007 saw a 150 percent increase in phishing scams and a 500 percent increase in malicious payloads. If you don't have the Adobe PDF fix yet, obtain the patch at Adobe's site.
- Page 1 of 2
- Next ยป
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
PCW Download Guide
Laptop Showcase
Tags at a Glance
Related Security Articles
- Schlage Introduces Web-controlled Door Locks A new line of deadbolt locks can be operated remotely using a Web browser or mobile phone.
- At the Front Lines of Protecting the Internet VeriSign's CTO on securing the DNS infrastructure and whether new identity certificates add any value.
- Phishing Attacks Get Personal Savvy users who talk back to phishers instead of falling for their traps are getting attacked again.
- Tech Staff Admit They'd Steal Secrets If Laid Off A survey reports 88 percent of IT staff would take sensitive company information with them when dismissed.
- Space Station Laptops Catch Virus Malware goes into orbit, infecting laptops on the International Space Station.
Best Prices on Security Software
Norton Internet Security 2008Price: $19.25
Internet Security 2008 - 3-User (Full Product, PC)Price: $12.99
Norton 360 2.0 ( PC)Price: $33.99
Internet Security Suite 2008 - 3-UserPrice: $18.95
Internet Security 7.0 - 3-UsersPrice: $19.95
Norton 360Price: $32.99
- Web Demo: Discover the Benefits of VoIP Is your company looking for a world class VoIP communications solution that will meet all of your business requirements? If so, join us for our Live Online Demo where you will receive a "guided tour" to the AltiGen Solution.
- PC World Webcast: Going Green Wondering how to make your business greener? These tips will help your business save money, and save the environment.
- A Windows Vista FAQ Corporate customers are deploying Windows Vista now, and Dell Services wants to help you understand the features of the new OS and how to plan your Windows Vista deployment.





"With Exploit Out, Microsoft Rushes IE 7 Fix" Comments