On the same day that Microsoft released seven new security bulletins for the Windows operating system, four new “extremely critical” vulnerabilities in the Internet Explorer Web browser were announced Tuesday by a Denmark-based computer security firm.
The vulnerabilities discovered by Secunia aren’t based on errors in the code of IE, according to Jerry Brady, chief services officer at VeriSign’s Managed Security Services (formerly Guardent). Instead, he said, they’re caused by weaknesses in the design of IE and of Web browsers in general. “You have to wonder if it ever makes sense in any case to accept code from a server and run it without authentication,” Brady said in an interview with eWEEK.com. “Web browsers have lots of things in their functionality now that are well beyond what their original purpose was. It’s hard to imagine a Web browser ever being very secure.”
Source: eWeek

Articles RSS