Microsoft Investigates IE 7 Vulnerability | CIO Insight

Microsoft Investigates IE 7 Vulnerability

Written By
Brian Prince
Brian Prince
Mar 15, 2007
2 minute read

Microsoft is investigating a new flaw uncovered in Internet Explorer 7 that opens users up to phishing attacks.

The vulnerability was discovered by noted Israel-based security researcher Aviv Raff. Using a cross-site scripting attack, an attacker can exploit a design flaw in IE 7, he wrote on his Web site.

He said an attacker can create a specially crafted navcancl.htm local resource link with a script that will display a fake content of a trusted site such as PayPal.

When the victim opens the link that was sent by the attacker, a “Navigation Canceled” page will be displayed, he said.

If the victim refreshes the page, the attacker’s provided content—a fake PayPal login page for example—will be displayed in an attempt to trick the user into believing he or she is on the actual site, he wrote.

In an interview with eWEEK, Raff said the vulnerability should be taken seriously.

“Well, it’s a serious threat, because a phisher can use it to take advantage of his victim without the need to create a fake URL,” he said.

“Until MS fixes this vulnerability, the user should not trust the “Navigation Canceled” page, and should not click on any link on that page.”

The vulnerability affects IE 7 on Windows Vista and XP.

A Microsoft spokesperson said in an e-mail to eWEEK the company was not aware of anyone actually trying to exploit the vulnerability.

The company will continue to investigate the matter and will take appropriate action when the investigation is completed, and urged anyone who feels that have been affected to contact Product Support Services.

Check out eWEEK.com’s Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK’s Security Watch blog.

CIO Insight Logo

CIO Insight offers thought leadership and best practices in the IT security and management industry while providing expert recommendations on software solutions for IT leaders. It is the trusted resource for security professionals who need to maintain regulatory compliance for their teams and organizations. CIO Insight is an ideal website for IT decision makers, systems integrators and administrators, and IT managers to stay informed about emerging technologies, software developments and trends in the IT security and management industry.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.