Date: November
23, 2005
Subject: Microsoft
Internet Explorer Vulnerability
Microsoft has
recently been informed that a security
vulnerability exists within Internet Explorer
which could potentially place millions of
computers at risk. All computers running Windows
XP Service Pack 2 or Windows 2000 Service Pack 4
are affected, even if they have been fully
patched.
At issue is a
flaw in the way in which Internet Explorer
handles certain JavaScript code. JavaScript is a
programming language that is used on the
internet primarily to offer a more full featured
browsing experience. Individuals taking
advantage of this security vulnerability could
ultimately gain complete control over any
compromised computer system.
At this time no
patch is available from Microsoft to repair the
vulnerability but one is anticipated over the
next couple of weeks. If you wish to take
precautionary measures against this security
vulnerability you can disable Active Scripting
using the following procedure:
1/ Close all
open applications
2/ Open
Internet Explorer
3/ Click on the
TOOLS menu
4/ Click on the
INTERNET OPTIONS sub-menu
5/ Click on the
SECURITY tab
6/ Ensure that
the INTERNET icon is selected and click on the
CUSTOM LEVEL button
7/ Scroll to
the bottom of the displayed list and then scroll
slowly upward until you see the SCRIPTING
heading
8/ Under the
ACTIVE SCRIPTING sub-heading select DISABLE
9/ Click on OK
10/ Click on OK
(again)
Once
Microsoft has released a patch to correct this
problem we will notify you so that you can
reverse this procedure to restore full internet
functionality.
As always, please do
not hesitate to contact me if you have any
questions about this or any other issue.
If you received this
bulletin from an associate and would like to be
added to our mailing list please contact us.
Previous issues of the ELM
Bulletin are
available from our website.
Please feel
free to forward these bulletins to anyone you
wish. If you no longer wish to receive these
bulletins, or if you received this bulletin by
mistake please send me an email with "Please
remove me" in the subject line and I will take
your name off of the bulletin mailing list.