Researchers Reveal New IE Zero-Day Vulnerability
UPDATE
Thursday, December 23, 2010 by DrJBHL | Discussion: Personal Computing
I wasn't planning on posting today, but when I read this, I felt I should whip something up quickly.
Security researchers have released attack code that exploits an unpatched bug in Microsoft's Internet Explorer (IE) and sidesteps defenses baked into Windows 7.
Microsoft late Wednesday confirmed that all versions of Internet Explorer (IE) contain a critical vulnerability that attackers can exploit by persuading users to visit a rigged Web site. The site can then hijack personal data and install malicious code and/or malware. This will bypass all security software and Windows 7 protestion. Network Administrators and IT Professionals can download EMET 2.0 from MS who claim it can be configured to protect servers.
MS Security Advisory (2488013) HERE.
Although the company said it would patch the problem, it is not planning to rush out an emergency update.
The next regularly-scheduled Patch Tuesday is Jan. 11, but because Microsoft usually updates the browser every other month, and just did so last week, it's possible the vulnerability won't be addressed until February.
Microsoft's usual practice is to release an emergency fix only if attacks appear and then grow in strength. Microsoft has never revealed how it sets the point at which a rush patch is triggered.
The vulnerability in IE6, IE7 and IE8 surfaced several weeks ago when French security firm Vupen disclosed a flaw in IE's HTML engine.
The bug first surfaced earlier this month when French security firm Vupen announced it had uncovered a flaw in IE's HTML engine, however the vulnerability was noted and explained earlier in a Chinese trade publication.
Doc suggests using Firefox, Opera, or any non iE based browser until this vulnerability is patched.

Reply #2 Thursday, December 23, 2010 2:28 PM
IE sucks. IE (and Microsoft in general) is and always has been the primary target for most hackers, malware, etc. Today there are too many great alternative browsers (FireFox, Opera, Safari, etc.) for anyone to be using it.... ![]()
Reply #3 Thursday, December 23, 2010 2:32 PM
Lightof Abraxis, it's called that "zero-day" -- because the flaw becomes public before a patch is ready to stop its exploitation.
Oh yes, you're welcome.
![]()
I agree Navagatsio, especially now that it's the buggiest and slowest of the browsers.
Reply #4 Thursday, December 23, 2010 4:51 PM
Never used IE any version. Always had Firefox. MS will never learn. Dopes!
Reply #5 Thursday, December 23, 2010 5:02 PM
The safest way to surf the web is through a Virtual PC session with whatever browser you choose.
As long as you disgard all changes when you close out your Virtual PC, there's no chance of infections or malware.
Reply #6 Thursday, December 23, 2010 5:07 PM
Tried BufferFree but didn't like what it did to the rest of my software.
Reply #7 Thursday, December 23, 2010 5:37 PM
Please elaborate. Virtual PC session?
Reply #8 Thursday, December 23, 2010 5:39 PM
Thanks again Doc, and thanks for including the link to the Advisory - it's well worth reading.
I keep thinking about trying out FireFox, mainly just for fun, now could be a good time.![]()
Reply #9 Thursday, December 23, 2010 5:46 PM
The 3.8 Beta is out...lotsa great extensions for earlier builds...not ready for the 3.8 yet.
The ff 4.0 should be out in January.
Opera 11 is blazing fast, and has really good extensions, too.
Reply #10 Thursday, December 23, 2010 5:57 PM
Well now that certainly sounds like a nice change from IE ![]()
Reply #11 Thursday, December 23, 2010 8:03 PM
I've been test driving FF4 Beta 7 & 8. Initial/home page loads fine but page loads in additional tabs are hanging for 20-30 seconds during which time FF is entirely unresponsive. Recovers but then happens again with the next page load.
FF3.6.13 is doing the same thing only when it hangs it stays crashed & has to be killed with TM.
No such troubles with IE7 on same pages.
I think I'll grab a copy of Opera & use it for a little while till FF gets things sorted out.
Reply #12 Thursday, December 23, 2010 8:23 PM
Virtual PC session
Please elaborate. Virtual PC session?
It' also called XP Mode in Windows 7.
Reply #13 Thursday, December 23, 2010 8:27 PM
IE with vulnerabilities ... never. /sarcasm
The only thing stopping my move from FF to Opera is Noscript. I hope someone will make an extension like it for Opera.
Opera does have problems with some web sites, but they are few and far between.
I have not had any major problems with FF4 Beta 7, only some add-ons won't work and my password manager dies. But with a beta of a browser you can't expect safe browsing.
Until then my clunky old FF will have to do. ![]()
Reply #14 Thursday, December 23, 2010 8:28 PM
My ff doesn't do that Daiwa, but Opera is really great. I think you;ll love it. ![]()
Reply #15 Thursday, December 23, 2010 8:45 PM
Not sure why the hangs/crashes are occurring here with FF3 & FF4, either, obviously. I've reported them to Mozilla so we'll see. First started to happen with 3.6.10 I believe. Had been using FF exclusively (with IE Tab 2 for those occasional finicky pages that just don't cotton to FF) for a long time and never had similar problems, even with 10 or more open tabs (doesn't happen often, but 5-6 is routine). They've made both FF3 & FF4 unusable during the workday, just no time to deal with reloads, repeat logins, etc.
I'm liking what I see of Opera so far (using it for this reply), but a real workday will tell the tale.
Reply #18 Thursday, December 23, 2010 10:10 PM
especially now that it's the buggiest and slowest of the browsers.
The problem is that 'vulnerability' could be anything from 'can look at the files in one directory' to 'can smite your box.' MS will usually fix vulnerabilities even when there isn't even a verifiable threat due to other safeguards.
I haven't used IE8 in ages but I've been back on the IE9 beta for a while and loving it. Can't wait for the RC.
Reply #19 Friday, December 24, 2010 12:09 AM
Reply #20 Friday, December 24, 2010 12:43 AM
yeah -started using noscript a few days ago. Not sure if this is a bad as it sounds in the OP from reading the security bulletin, but doesn't matter much to me as I'm using firefox.
Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!







Reply #1 Thursday, December 23, 2010 2:28 PM
Thanks for the heads up. As an aside, does anyone know why they call them Zero-day vulnerabilities? I've always wondered.