SHARE
Facebook X Pinterest WhatsApp

IE Drag-and-Drop Flaw Warning

Written By
thumbnail
Ryan Naraine
Ryan Naraine
Aug 19, 2004

A security bug in Microsoft Internet Explorer’s drag-and-drop feature could put
millions of Web surfers at risk of malicious hacker attacks, researchers
warned on Thursday.

According to a Secunia alert, the flaws,
detected and reported by http-equiv, affect IE versions
5.01, 5.5 and 6.0 on fully patched systems running Microsoft Windows XP
SP1 or SP2.

Secunia rated the flaws “highly critical” and urged IE users to
disable the browser’s Active Scripting feature.

The company said the vulnerability is caused by insufficient
validation of drag-and-drop events issued from the “Internet” zone to
local resources. An attacker could potentially plant a harmful
executable file in a user’s startup folder, which will
execute the next time Windows boots.

A proof-of-concept exploit, which plants a program in the startup
directory when a user drags a program masqueraded as an image, has been
released by http-equiv.

“Even though the PoC depends on the user performing a drag-and-drop
event, it may potentially be rewritten to use a single click as user
interaction instead,” Secunia warned.

The latest flaws closely resemble vulnerabilities discovered
last November by Chinese researcher Liu Die Yu. Those bugs, which has
since been fixed, put IE users at risk of system access, exposure of
sensitive information, cross site scripting and security bypass.

Recommended for you...

Best Internet Security Software
Devin Partida
Mar 23, 2022
HP Wolf Security Report Shows Threat Landscape Getting Scarier
Rob Enderle
Oct 15, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
The Coming AI Threats We Aren’t Prepared For
Rob Enderle
Aug 27, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.