Posts Tagged ‘MS09-002’

Navigation Canceled – IE Patch Breaks Security to Improve Security?

Friday, February 20th, 2009

By default, Internet Explorer 7 sets sites in the Internet Zone where “Protected Mode” (PM) is enabled. PM prevents IE from saving files and/or settings via IE without prompting the user for approval. PM is a good thing.

Sites in the Trusted Sites Zone, by default, do not have PM on. Consider it like this, if you trust a site enough to put it in the Trusted Sites Zone then why have PM on?

MS09-002 is the latest Cumulative Update for IE. In that patch, we believe Microsoft introduced a modification to the way it treats the About: page. Thus far no details can be found other than what is contained in their KnowledgeBase article 967941, so our interpretation may not be strictly accurate.

(more…)