DrJBHL DrJBHL

Researchers Reveal New IE Zero-Day Vulnerability

Researchers Reveal New IE Zero-Day Vulnerability

UPDATE

 

I wasn't planning on posting today, but when I read this, I felt I should whip something up quickly.

Security researchers have released attack code that exploits an unpatched bug in Microsoft's Internet Explorer (IE) and sidesteps defenses baked into Windows 7.

Microsoft late Wednesday confirmed that all versions of Internet Explorer (IE) contain a critical vulnerability that attackers can exploit by persuading users to visit a rigged Web site. The site can then hijack personal data and install malicious code and/or malware. This will bypass all security software and Windows 7 protestion. Network Administrators and IT Professionals can download EMET 2.0 from MS who claim it can be configured to protect servers.

MS Security Advisory (2488013) HERE.

Although the company said it would patch the problem, it is not planning to rush out an emergency update.

The next regularly-scheduled Patch Tuesday is Jan. 11, but because Microsoft usually updates the browser every other month, and just did so last week, it's possible the vulnerability won't be addressed until February.

Microsoft's usual practice is to release an emergency fix only if attacks appear and then grow in strength. Microsoft has never revealed how it sets the point at which a rush patch is triggered.

The vulnerability in IE6, IE7 and IE8 surfaced several weeks ago when French security firm Vupen disclosed a flaw in IE's HTML engine.

The bug first surfaced earlier this month when French security firm Vupen announced it had uncovered a flaw in IE's HTML engine, however the vulnerability was noted and explained earlier in a Chinese trade publication.

Doc suggests using Firefox, Opera, or any non iE based browser until this vulnerability is patched.

 

 

164,931 views 95 replies
Reply #76 Top

Quoting DaveRI, reply 75
Makes me just want to run out and buy more stuff from Microsoft.  Mooooo. 
End of DaveRI's quote

One thing I can promise, DaveRI... as iOs and OSX become more popular, and as Android does as well, they will become targets as well. I'm only sorry we don't have really super cyber systems to find and fry the lice who create the worms/viruses, etc.

Reply #77 Top

If you email them, use the link to WC...who knows who might get interested!
End of quote

You got it Doc. I'm gonna make like a commercial. lol

Reply #78 Top

Doc I'm not annoyed with MS because they're a target, I'm annoyed because they appear to be so complacent about closing the barn door just because the horses haven't started wandering out yet. ;)

Reply #79 Top

I'm annoyed at the creeps that perform these attacks for no comprehensible reason.

Reply #80 Top

Maybe someone will find a way  to piggy-back one of these nasties and send it right back at 'em. Serve them right to get a taste of their own medicine.

Reply #81 Top

Quoting Uvah, reply 80
Maybe someone will find a way  to piggy-back one of these nasties and send it right back at 'em. Serve them right to get a taste of their own medicine.
End of Uvah's quote

 

I'm sure they have theirs already patched and protected.

Reply #82 Top

No doubt. Sneaky suckers.

Reply #83 Top

Quoting DaveRI, reply 78
Doc I'm not annoyed with MS because they're a target, I'm annoyed because they appear to be so complacent about closing the barn door just because the horses haven't started wandering out yet.
End of DaveRI's quote

I think that is indicative of all companies.  It is not a problem until a few horses are gone (at least).

Reply #84 Top

I think that is indicative of all companies. It is not a problem until a few horses are gone (at least).
End of quote

Agreed.  Unfortunate, but agreed.

Reply #85 Top

Mini rant. Are doctors the only ones smart enough to know the meaning of preventative medicine?

Reply #86 Top

Who says we're that smart? 8(| :-"

Reply #87 Top

Quoting Uvah, reply 85
Mini rant. Are doctors the only ones smart enough to know the meaning of preventative medicine?
End of Uvah's quote

Do doctors usually treat patients with untested medicines?

Oh hey, you might lose a leg, but you'll feel better!  For the moment.

Reply #89 Top

Think of it this way. A pre-emptive strike against the bad guys 'before' they get a chance to do the nasty. This is what Microstuff doesn't understand.

Reply #90 Top

The fact is that MS is approaching the problem calmly. They have MAPP working on a solution/mitigation, but are doing it at their own pace. You can say, "That's not fast enough.", but MS will do as it sees best and least expensive/disruptive, especially at this time with CES going on.

There have been no reports yet of the problem surfacing.

Reply #92 Top

Very informative. Thanks for the link.

Reply #93 Top

Hey, DrJBHL -

Opera 11.00 is eating my replies here lately.  Keep getting this error message when I click 'Submit':

The reply that you tried to make got all jumbled on the way to our server. Please wait a moment and try again.
End of quote

Appears just below the 'Quick Reply' header.  Had to pop over to FF4.0B9 to post this.

You having any such trouble?  Thx.

Reply #94 Top

Quoting Daiwa, reply 93
Hey, DrJBHL -

Opera 11.00 is eating my replies here lately.  Keep getting this error message when I click 'Submit':

The reply that you tried to make got all jumbled on the way to our server. Please wait a moment and try again.

Appears just below the 'Quick Reply' header.  Had to pop over to FF4.0B9 to post this.

You having any such trouble?  Thx.
End of Daiwa's quote

No, Daiwa.... Posted with Opera 11.

Reply #95 Top

I experienced the same problem which is why I stopped using it. Too bad though as Opera is a screamer.