Microsoft Issues IE Security Alert | Internet News

Microsoft Issues IE Security Alert

Written By
Andy Patrizio
Andy Patrizio
Oct 11, 2007
1 minute read

Microsoft has issued a rare out-of-pocket security alert concerning the current version of Internet Explorer. The newly discovered vulnerability affects Windows XP, Server 2003 and Windows 2000 but not Vista, and it does not affect Internet Explorer 6.0 or earlier. It only involves XP/2000/Server 2003 running IE 7.

In a posting to its security blog, Microsoft said the threat presents itself when Windows does not correctly handle specially crafted URLs or URIs that are passed to it.

Internet Explorer 7 updates a Windows component, which modifies the interaction between Internet Explorer and Windows Shell when handling URLs and URI’s. Applications that pass un-validated URIs or URLs to Windows can be leveraged to exploit this vulnerability.

In order for an attack to be carried out, a user must trigger an un-validated, specially crafted URL or URI in an application. For example, a user could click on a link in an e-mail message, which could allow arbitrary code to be run in the context for the logged on user.

For a more in-depth examination of the error, Microsoft’s Security team has posted a lengthy technical discussion on the flaw.

Microsoft’s only recommendations at this point are to keep a firewall running on user machines and check for updates, which would indicate a fix is coming outside of its normal monthly Patch Tuesday schedule.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.