Microsoft Issues 'Fix It' as It Investigates MHTML Vulnerability in IE

Microsoft released Security Advisory 2501696 in response a scripting vulnerability in Internet Explorer that affects all versions of Windows.

The security hazard is found in the MIME Encapsulation of Aggregate HTML (MHTML) protocol handler. The attach mechanism is similar to a server-side cross-site-scripting (XSS) exploit, in which a malicious script could run on a user's computer after clicking on a link.

While this vulnerability could be exploited by hackers, the chances of an attack are slim, according to some software security analysts.

"At first glance today's advisory looks grim because it affects every supported Windows platform," wrote Andrew Storms, director of information and technology at software security firm nCircle, in a released statement.  "However, even though the proof of concept code is public, carrying out an attack using this complicated cross site scripting-like bug will not be easy."

While there currently is no patch to fix the vulnerability, Microsoft suggested a workaround. This mitigation approach disables MHTML handler scripting by setting all corresponding keys in the Windows registry. Microsoft issued a "Fix it" in a KnowledgeBase article to automate the workaround.

Wolfgang Kandek, CTO of Qualys, offered another option to avoid the vulnerability: use an alternative browser.

"While the vulnerability is located in a Windows component, Internet Explorer is the only known attacker vector," Kandek wrote in a blog posting.  "Firefox and Chrome are not affected in their default configuration, as they do not support MHTML without the installation of specific add-on modules."

The hole was first brought to the attention by individuals on the WooYun Web site. This is the same site that divulged information about the vulnerability in the CSS handler of Internet Explorer in December.

Coupled with a handful of security concerns last month, Microsoft has been busy with multiple vulnerabilities as of late. "2011 is not off to an auspicious start for Microsoft's security staff," wrote Storms. "In early January Jonathan Ness posted an explanation of five public security bugs Microsoft was tracking to the SRD blog. Today, just two short weeks later, we have another one to add to the list."

About the Author

Chris Paoli (@ChrisPaoli5) is the associate editor for Converge360.

Featured

  • From Fire TV to Signage Stick: University of Utah's Digital Signage Evolution

    Jake Sorensen, who oversees sponsorship and advertising and Student Media in Auxiliary Business Development at the University of Utah, has navigated the digital signage landscape for nearly 15 years. He was managing hundreds of devices on campus that were incompatible with digital signage requirements and needed a solution that was reliable and lowered labor costs. The Amazon Signage Stick, specifically engineered for digital signage applications, gave him the stability and design functionality the University of Utah needed, along with the assurance of long-term support.

  • college student working on a laptop, surrounded by icons representing campus support services

    National U Launches Student Support Hub for Non-Traditional Learners

    National University has launched a new student support hub designed to help online and working learners balance career, education, and family responsibilities as they pursue their education. Called "The Nest," the facility is positioned as a "co-learning" center that provides wraparound support services, work and study space, and access to child care.

  • Three cubes of noticeably increasing sizes are arranged in a straight row on a subtle abstract background

    A Sense of Scale

    Gardner Campbell explores the notion of scale in education and shares some of his own experience "playing with scale" — scaling up and/or scaling down — in an English course at VCU.

  • AI microchip, a cybersecurity shield with a lock, a dollar coin, and a laptop with financial graphs connected by dotted lines

    Survey: Generative AI Surpasses Cybersecurity in 2025 Tech Budgets

    Global IT leaders are placing bigger bets on generative artificial intelligence than cybersecurity in 2025, according to new research by Amazon Web Services (AWS).