Scripting Vulnerability Detected in MS IE and Outlook Express
Christine Gordon of
InternetNews reports that "yet another security flaw has popped-up on Microsoft Corp.'s Internet Explorer 5.x and Outlook Express E-mail service.
This time, even when Active Scripting is disabled, it continues to execute -- allowing would-be hackers to use HTML-formatted messages to read files on a user's machine."
Microsoft has been alerted and says that a fix is available.
Scripting Vulnerability Detected in MS IE and Outlook Express (InternetNews, April 20, 2001)