Researchers Reveal New IE Zero-Day Vulnerability

UPDATE

Thursday, December 23, 2010 by DrJBHL | Discussion: Personal Computing

 

I wasn't planning on posting today, but when I read this, I felt I should whip something up quickly.

Security researchers have released attack code that exploits an unpatched bug in Microsoft's Internet Explorer (IE) and sidesteps defenses baked into Windows 7.

Microsoft late Wednesday confirmed that all versions of Internet Explorer (IE) contain a critical vulnerability that attackers can exploit by persuading users to visit a rigged Web site. The site can then hijack personal data and install malicious code and/or malware. This will bypass all security software and Windows 7 protestion. Network Administrators and IT Professionals can download EMET 2.0 from MS who claim it can be configured to protect servers.

MS Security Advisory (2488013) HERE.

Although the company said it would patch the problem, it is not planning to rush out an emergency update.

The next regularly-scheduled Patch Tuesday is Jan. 11, but because Microsoft usually updates the browser every other month, and just did so last week, it's possible the vulnerability won't be addressed until February.

Microsoft's usual practice is to release an emergency fix only if attacks appear and then grow in strength. Microsoft has never revealed how it sets the point at which a rush patch is triggered.

The vulnerability in IE6, IE7 and IE8 surfaced several weeks ago when French security firm Vupen disclosed a flaw in IE's HTML engine.

The bug first surfaced earlier this month when French security firm Vupen announced it had uncovered a flaw in IE's HTML engine, however the vulnerability was noted and explained earlier in a Chinese trade publication.

Doc suggests using Firefox, Opera, or any non iE based browser until this vulnerability is patched.

 

 

First Previous Page 5 of 5 Next Last
DaveBax
Reply #81 Friday, January 7, 2011 9:28 PM

Maybe someone will find a way  to piggy-back one of these nasties and send it right back at 'em. Serve them right to get a taste of their own medicine.

 

I'm sure they have theirs already patched and protected.

Uvah
Reply #82 Friday, January 7, 2011 9:31 PM

No doubt. Sneaky suckers.

Dr Guy
Reply #83 Monday, January 10, 2011 10:37 AM

DaveRI
Doc I'm not annoyed with MS because they're a target, I'm annoyed because they appear to be so complacent about closing the barn door just because the horses haven't started wandering out yet.

I think that is indicative of all companies.  It is not a problem until a few horses are gone (at least).

DaveRI
Reply #84 Monday, January 10, 2011 12:44 PM

I think that is indicative of all companies. It is not a problem until a few horses are gone (at least).

Agreed.  Unfortunate, but agreed.

Uvah
Reply #85 Monday, January 10, 2011 8:11 PM

Mini rant. Are doctors the only ones smart enough to know the meaning of preventative medicine?

Daiwa
Reply #86 Monday, January 10, 2011 8:55 PM

Who says we're that smart?

Savyg
Reply #87 Monday, January 10, 2011 9:30 PM

Mini rant. Are doctors the only ones smart enough to know the meaning of preventative medicine?

Do doctors usually treat patients with untested medicines?

Oh hey, you might lose a leg, but you'll feel better!  For the moment.

DrJBHL
Reply #88 Monday, January 10, 2011 10:19 PM

Slightly OT but the answer is 'No'. In pre-clinical use settings (experimental) they can be used provided permission for the protocols are obtained.

http://medical-dictionary.thefreedictionary.com/phase+study

Uvah
Reply #89 Tuesday, January 11, 2011 7:42 AM

Think of it this way. A pre-emptive strike against the bad guys 'before' they get a chance to do the nasty. This is what Microstuff doesn't understand.

DrJBHL
Reply #90 Tuesday, January 11, 2011 8:12 AM

The fact is that MS is approaching the problem calmly. They have MAPP working on a solution/mitigation, but are doing it at their own pace. You can say, "That's not fast enough.", but MS will do as it sees best and least expensive/disruptive, especially at this time with CES going on.

There have been no reports yet of the problem surfacing.

Savyg
Reply #91 Wednesday, January 12, 2011 10:35 PM
Uvah
Reply #92 Thursday, January 13, 2011 8:24 AM

Very informative. Thanks for the link.

Daiwa
Reply #93 Monday, January 17, 2011 11:26 PM

Hey, DrJBHL -

Opera 11.00 is eating my replies here lately.  Keep getting this error message when I click 'Submit':

The reply that you tried to make got all jumbled on the way to our server. Please wait a moment and try again.

Appears just below the 'Quick Reply' header.  Had to pop over to FF4.0B9 to post this.

You having any such trouble?  Thx.

DrJBHL
Reply #94 Tuesday, January 18, 2011 12:01 AM

Hey, DrJBHL -

Opera 11.00 is eating my replies here lately.  Keep getting this error message when I click 'Submit':

The reply that you tried to make got all jumbled on the way to our server. Please wait a moment and try again.

Appears just below the 'Quick Reply' header.  Had to pop over to FF4.0B9 to post this.

You having any such trouble?  Thx.

No, Daiwa.... Posted with Opera 11.

Uvah
Reply #95 Tuesday, January 18, 2011 5:43 AM

I experienced the same problem which is why I stopped using it. Too bad though as Opera is a screamer.

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01