Things Just Got Worse For Internet Explorer Users: Unpatched Exploit Code Released
Posted By Pallab De On March 11, 2010 @ 2:17 pm In Tech News | No Comments
Earlier this week, Microsoft had issued a security advisory [1] warning users of Internet Explorer 6 and 7 about the presence of an unpatched vulnerability. Since, then the situation has rapidly deteriorated for Microsoft. Multiple security product vendors including Symantec and McAfee [2] have already confirmed that the vulnerability is being exploited by hackers to attack unsuspecting users. Now, PCWorld [3] is reporting that the exploit code has been published on the web.
The vulnerability, which has been rated by Secunia [4] as “Extremely critical”, permits the execution of arbitrary code that can result in a compromised system. The exploit code was published [5] by Israeli researcher Moshe Ben Abu, who used a clue present in a blog post [6] by McAfee [2] to obtain an in-the-wild exploit.
The critical nature of the vulnerability combined with the publication of exploit code makes the situation precarious for Internet Explorer 6 and 7 users. Most experts believe that Microsoft will try to patch the vulnerability as soon as possible. However, until a patch is released, users are advised to use an alternate browser or apply the workarounds [7] suggested by Microsoft.
Article printed from Techie Buzz: http://techie-buzz.com
URL to article: http://techie-buzz.com/tech-news/ie-0-day-vulnerability-code-published.html
URLs in this post:
[1] security advisory: http://www.microsoft.com/technet/security/advisory/981374.mspx
[2] McAfee: http://goo.gl/SbeZ
[3] PCWorld: http://www.pcworld.com/article/191268/ie_zero_day_exploit.html
[4] Secunia: http://secunia.com/advisories/38860
[5] published: http://www.rec-sec.com/2010/03/10/internet-explorer-iepeers-use-after-free-exploit/
[6] blog post: http://www.avertlabs.com/research/blog/index.php/2010/03/09/targeted-internet-explorer-0day-attack-announced-cve-2010-0806/
[7] workarounds: http://www.microsoft.com/technet/security/advisory/981374.mspx#ENCAC
Click here to print.
Copyright © 2006-20011 Techie Buzz. All rights reserved.