McAfee says browser flaw allowed breach

Published 4:00 am Friday, January 15, 2010

SAN FRANCISCO — Security software maker McAfee Inc. said Thursday that a flaw in Microsoft Corp.’s Internet browser was exploited in recent cyber-attacks on Google Inc. and others that have caused the search giant to consider pulling out of China.

George Kurtz, McAfee’s worldwide chief technology officer, wrote on a company Web site that McAfee has informed Microsoft about the flaw in its Internet Explorer browser, and that Microsoft is expected to soon publish a related advisory.

“We are working with multiple organizations that were impacted by this attack, as well as the government and law enforcement,” Kurtz wrote. “These attacks will look like they come from a trusted source, leading the target to fall for the trap and clicking a link or file. That’s when the exploitation takes place, using the vulnerability in Microsoft’s Internet Explorer.”

Marketplace