X

First IE7 flaw in some doubt

First IE7 flaw in some doubt

Robert Vamosi Former Editor
As CNET's former resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security.
Robert Vamosi
Writing in today's , Christopher Budd said that security vendor reports of a vulnerability existing within the newly released Internet Explorer 7 are false. The vulnerability exists, but within Outlook Express; Internet Explorer is merely the vector for exploitation. Sure enough, there's an April 2006 security alert #19738 from Secunia discussing pretty much the same flaw within IE6. It calls out Outlook Express as the culprit. Given that the vulnerability, whatever the cause, can result in the remote access of data, one has to wonder why Microsoft didn't patch this flaw six months ago.