Researchers Reveal New IE Zero-Day Vulnerability
UPDATE
Thursday, December 23, 2010 by DrJBHL | Discussion: Personal Computing
I wasn't planning on posting today, but when I read this, I felt I should whip something up quickly.
Security researchers have released attack code that exploits an unpatched bug in Microsoft's Internet Explorer (IE) and sidesteps defenses baked into Windows 7.
Microsoft late Wednesday confirmed that all versions of Internet Explorer (IE) contain a critical vulnerability that attackers can exploit by persuading users to visit a rigged Web site. The site can then hijack personal data and install malicious code and/or malware. This will bypass all security software and Windows 7 protestion. Network Administrators and IT Professionals can download EMET 2.0 from MS who claim it can be configured to protect servers.
MS Security Advisory (2488013) HERE.
Although the company said it would patch the problem, it is not planning to rush out an emergency update.
The next regularly-scheduled Patch Tuesday is Jan. 11, but because Microsoft usually updates the browser every other month, and just did so last week, it's possible the vulnerability won't be addressed until February.
Microsoft's usual practice is to release an emergency fix only if attacks appear and then grow in strength. Microsoft has never revealed how it sets the point at which a rush patch is triggered.
The vulnerability in IE6, IE7 and IE8 surfaced several weeks ago when French security firm Vupen disclosed a flaw in IE's HTML engine.
The bug first surfaced earlier this month when French security firm Vupen announced it had uncovered a flaw in IE's HTML engine, however the vulnerability was noted and explained earlier in a Chinese trade publication.
Doc suggests using Firefox, Opera, or any non iE based browser until this vulnerability is patched.

Reply #42 Friday, December 24, 2010 6:34 PM
Why would you use something called Internet Exploder ![]()
Reply #43 Friday, December 24, 2010 6:39 PM
Kablaam! There goes IE. Good thing I got FF. ![]()
Reply #44 Friday, December 24, 2010 7:57 PM
I have FF, Opera, and Google Chrome.
I've used FF since it first came out and have a hard time forcing myself to try anything else.
I like Operas speed. I like Opera Unite. I already had Dave Baxter stream my music collection and I use it to stream my music around the house.
I have WIndows7 on the other PC and have forced myself to run only Google Chrome for everything, including email. I have FF and TB exe sitting in a folder and have been tempted to install 'em but have held off.
I'm really starting to get comfortable with Google Chrome. I have fewer add-ons than I do with FF. The lack of add-ons has been an issue in giving up FF, but after using Opera and Chrome, I realize I have a lot of add-ons in FF that I don't need and are probably slowing it down.
On a side note...occasionally I have downloaded Seamonkey. I think it has great potential but is slow in development. I mess with it and uninstall it after a few weeks and download the next big update. It's not bad, just not as customizable as the three above.
And finally, there is ROckmelt, which I am REALLY liking for Facebook. (I have invites for, btw.)
I stopped using IE years ago. If not for Windows/MIcrosoft updates I would uninstall the damn thing so as not to worry about someone else getting on it.
Reply #45 Friday, December 24, 2010 8:38 PM
Reply #46 Friday, December 24, 2010 8:50 PM
Completely forgotten about SeaMonkey. I figured Mozilla was too busy with FF, TBird, etc. to still have it in development. ![]()
Reply #47 Saturday, December 25, 2010 5:50 AM
I started with FF. Am now running Opera. Do I want to run Google Chrome, SeaMonkey or yet another browser. Hmmmmmmm.
Reply #48 Saturday, December 25, 2010 6:08 AM
If you're happy with Opera's performance (sorry about the pun), why install more stuff? You'll end up with a crudded up registry and slow-downs.
Reply #49 Saturday, December 25, 2010 6:46 AM
Nah ... no more stuff. I got enough. Did install AdBlocker Plus though.
Reply #50 Saturday, December 25, 2010 12:03 PM
I didn't think you'd seen it, and didn't want your computer to be possibly vulnerable until February.
http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/
That guy thinks IE8 is one of the more secure browsers.
I'm not using IE8 anyway, so I'm not terribly worried.
Reply #51 Saturday, December 25, 2010 12:49 PM
TRUE OR FALSE:
1. Even if an alternate browser is used (eg. Firefox), and IE still remains on the system, that system is still vulnerable.
2. One can be safe from IE vulnerabilities only when IE is removed completely from the system.
3. Removing IE completely from the system will not in anyway harm the system.
![]()
Reply #53 Saturday, December 25, 2010 2:38 PM
aeligos:
Microsoft has issued an advisory for an unpatched vulnerability affecting all versions of Internet Explorer on all platforms. The vulnerability could allow a malicious Web page to trigger a denial of service or remote code execution in the context of the IE user. Exploit code for the vulnerability has been published, but there are no reports yet of active exploits in the wild.
The vulnerability is of a type known as "use-after-free" and is in the CSharedStyleSheet::Notify function in the CSS parser in mshtml.dll. Multiple @import calls in the attack document trigger the vulnerability. It was first reported by wooyun.org.
The exploit bypasses Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP) by taking advantage of a library it loads (mscorie.dll). This was not compiled with the /DYNAMICBASE option that enables ASLR and therefore loads predictably at the same address. Microsoft doesn't say why this, and apparently other libraries, weren't compiled with this option, but suggests that you use its Enhanced Mitigation Experience Toolkit (EMET 2.0) to force all loaded DLLs to dynamically rebase. This change should make the exploits highly unlikely to succeed. A video on the Microsoft Web site demonstrates the process.
Microsoft also stresses that protected mode in Internet Explorer 7 and 8 on Windows Vista, Windows 7, and Windows Server 2008 mitigate the vulnerability by limiting the privileges of attack code that succeeds in exploiting the vulnerability.
--------------------------------------------------
1. Mitigates does not mean prevents. It means 'decreases'. They don't say how much.
2. Highly unlikely also does not mean you are safe.
Reply #54 Saturday, December 25, 2010 3:12 PM
He mentioned something about not installing Flash. I have Flash player. Is that the open door?
Reply #55 Saturday, December 25, 2010 4:18 PM
Flash is vulnerable to other things:
Latest Vulnerabilities in Flash Player:
A recent vulnerability in the latest Adobe Flash version lead to a massive attack yesterday (12/24/10).
More than 220,000 pages on the Internet have been hacked most likely with an automated tool using a SQL injection attack. Those pages, some of well respected companies such as Nokia but also many non-profit organizations and town websites, redirect the user to websites that host the exploits for the Flash vulnerability.
If the system meets the requirements the exploit is used to download and execute trojans that steal information and droppers that download additional trojans. Information that are stolen are for example World of Warcraft account information while the droppers download files that add the computer to a botnet. (according to Trendmicro)
Most antivirus companies have already updated their software to disable the possibility that this exploit can be used on the computer the software is running on.
Your best bet if you do not use antivirus software is to either disable Flash for now or use an extension like NoScript to block Flash on every domain but trusted ones.
Reply #56 Sunday, December 26, 2010 6:01 AM
What if I just get rid of Flash player? If it isn't there no vulnerability ... right? I could uninstall it.
Reply #57 Sunday, December 26, 2010 6:10 AM
Correct Savyg. Sorry not to have responded sooner. Here are the latest patches/fixes for Mozilla browsers/email vulnerabilities. You'll note these problems have been addressed and fixed.
Opera vulnerability:
http://www.infoworld.com/d/security-central/opera-software-patch-browser-vulnerability-soon-046
Mozilla vulnerabilities:
Reply #58 Sunday, December 26, 2010 11:40 AM
Trivia: The date on the Opera link is March 2010. The date on the MS Advisory in OP is December 2010. Seems like the MS Advisory should have included: "We further advise that you do not hold your breath while waiting on us to patch this." ![]()
(still loving my new Opera toy
)
Reply #59 Sunday, December 26, 2010 12:05 PM
I upgrade FF to version 3.6.13 yesterday. So far so good. Have a question about Opera though. When I open it the browser goes to the last page it remembers not to the current page like FF does. Why is that?
Reply #60 Sunday, December 26, 2010 12:38 PM
Uvah, just follow the numbers in the screenshot.

Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!







Reply #41 Friday, December 24, 2010 6:14 PM
Must have been a busted download. I dl'd it again and this time it worked. Now I can play.