IE 6.x may allow malicious websites to invoke regedit.exe

A

Andy Carroll

While intending to visit the kitchen supply company
kohler.com I inadvertantly mistyped the url as
www.kholer.com. The website kholer.com immediately popped
up a dialog, which I dismissed, and then IE 6.x exited.

Upon further investigation I discovered that the "date
accessed" on c:\windows\regedit.exe had been updated to
the exact time that I inadvertantly visited the kholer.com

I have not executed regedit anytime within the past few
days - thus I suspect that the website www.kholer.com has
figured out a way to invoke regedit.exe.

Since I was logged on with administrator privileges at
the time presumably if the website did indeed execute
regedit.exe it may have been successful in modifying the
registry.

I am running McAfee Security Center and it reports the
version of Virus Scan as Build 8.0.41 version 4.3.20 DAT
version 4.0.4380

Virus Scan has not reported anything unusual.

Is anyone aware of any mechanism that allows malicious
websites to execute regedit.exe? Presumably this would
be a very bad thing.....

Cheers,


Andy Carroll
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top