New zero-day vulnerability identified in all versions of IE
The vulnerability, which could allow remote code execution, is being used in "limited, targeted attacks," according to an advisory issued by Microsoft. While all versions of the web browser, IE 6 through 11, are affected by the vulnerability, attacks are currently targeting IE versions 9, 10 and 11, according to security firm FireEye, which first reported the flaw Friday.
The attack leverages a previously unknown "use after free" vulnerability -- data corruption that occurs after memory has been released -- and bypasses both Windows DEP (data execution prevention) and ASLR (address space layout randomization) protections, according to FireEye.
The vulnerability is currently being exploited by a group of hackers targeting financial and defense organization in the US, FireEye told CNET.
"The APT [advanced persistent threat] group responsible for this exploit has been the first group to have access to a select number of browser-based 0-day exploits (e.g. IE, Firefox, and Flash) in the past," FireEye said. "They are extremely proficient at lateral movement and are difficult to track, as they typically do not reuse command and control infrastructure."
FireEye said the flaw was significant because it affects more than a quarter of the total browser market.
"Collectively, in 2013, the vulnerable versions of IE accounted for 26.25% of the browser market," FireEye said in its advisory.
An attack could be triggered by luring visitors to a specially crafted web page, Microsoft explained.
"The vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated," Microsoft said. "The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer."
Microsoft said it is investigating the vulnerability and may issue an out-of-cycle security update to address the issue.
We here at TheTechGame suggest using either Chrome (www.google.com/chrome) or Firefox (www.getfirefox.com) but whatever you do, don't continue to use Internet Explorer.
Posted:
Related Forum: PC General Forum
Source: http://www.cnet.com/news/new-zero-day-vulnerability-identified-in-all-versions-of-ie/
Related Articles
Comments
leiPosted:
Free_yoghurt i dont really like ie that much
Same Its really slow and other browsers are just such simpler. Safari is what I use.
leiPosted:
DanimalsTSNYCmy school uses chrome personallyMissWarzoh3OH3My school does! looks like i gotta talk to my school.iTypp Good thing no one uses IE
I work as a pc support tech for my university and 90% of the faculty at my school use IE. It's a real problem
Yea I think a lot of schools and offices still use IE. This could effect them big time.[/
Yeah most places don't even bother changing it so I imagine it will have a big effect on them
my school uses it but they also have google chrome so i just use that
DanimalsPosted:
TSNYCMissWarzoh3OH3My school does! looks like i gotta talk to my school.iTypp Good thing no one uses IE
I work as a pc support tech for my university and 90% of the faculty at my school use IE. It's a real problem
Yea I think a lot of schools and offices still use IE. This could effect them big time.
Yeah most places don't even bother changing it so I imagine it will have a big effect on them
my school uses it but they also have google chrome so i just use that
TSNYCPosted:
MissWarzoh3OH3My school does! looks like i gotta talk to my school.iTypp Good thing no one uses IE
I work as a pc support tech for my university and 90% of the faculty at my school use IE. It's a real problem
Yea I think a lot of schools and offices still use IE. This could effect them big time.
Yeah most places don't even bother changing it so I imagine it will have a big effect on them
XMEPosted:
I don't like IE but i do know a lot of people who use it and this can be very helpful to them
TreyarchedPosted:
Gossip I don't think anybody really uses IE anymore...
It's the 2nd most used browser so it's still used by millions of people
kitypurryPosted:
Stop hopping on the bandwagon on hating IE. IE was beyond our time when it came out and with continued support it turned into a splendid browser for touchscreen devices that's fast and fluent. I'm a chrome user on a desktop/laptop, but when it comes to any touch screen monitor it's IE all the way.
Latest Downloads
- 01. SnowRunner: SaveGame (all trucks are open) [32.1](1)
- 02. [PS4/EU] Hatsune Miku: Project DIVA Future Tone 100% Trophy Save(1)
- 03. Silent Hill 2 Remake: SaveGame (Motel Jacks, NG+)(0)
- 04. Phasmophobia: SaveGame (XX-2000, $594,965,799, 3 apocalypse skulls + bonus)(2)
- 05. Satisfactory: SaveGame (Observation deck)(1)
- 06. [EU] Sniper Elite 5 - Best Of The Best (CUSA16075)(5)
- 07. Voices Of The Void: SaveGame (All improvements for work + 7 days passed) [0.8.0](1)
- 08. Silent Hill 2 Remake: SaveGame (NG+, ending "Maria")(1)
- 09. Five Nights at Freddy's- Security Breach Save(8)
- 10. Commandos 2 - HD Remaster: SaveGame (All missions are open)(0)
- 11. Black Myth: Wukong - SaveGame (100%, NG++)(3)
- 12. Mindjack save xbox(0)
- 13. mindjack ps3 save(0)
- 14. Lies of P: SaveGame (game completed 6 times, hero level 124)(1)
- 15. Shadow of the Ninja - Reborn: SaveGame(0)
Latest Tutorials
- 01. PS3 HEN - Audio via a USB headset.(289)
- 02. Stumble Guys | Social Butterfly Achievement(194)
- 03. Last Days of Lazarus Achievement Walkthrough (Xbox/PS)(1,452)
- 04. EDENGATE: The Edge of Life - 100% Trophy/Achievement Guide(1,818)
- 05. Sherlock Holmes Chapter One | Walkthrough | No Commentary(1,459)
- 06. Morbid: The Seven Acolytes | Full Game Walkthrough(2,422)
- 07. Adam Wolfe | Full Game Walkthrough | No Commentary(1,569)
- 08. ALFRED HITCHCOCK: VERTIGO - 100% Walkthrough(1,877)
- 09. SHERLOCK HOLMES THE AWAKENED | Walkthrough | No Commentary(1,328)
- 10. Space Roguelike Adventure | Guide - Cheat Code!(1,525)
- 11. DETECTIVE Stella Porta Case | Trophy & Achievement Guide(1,188)
- 12. Tunic 100% Platinum Walkthrough | Trophy & Achievement Guide(1,813)
- 13. Outbreak: The Nightmare Chronicles Achievement Walkthrough(1,455)
- 14. Full Void 100% - Trophy & Achievement Guide(1,438)
- 15. Outbreak: Lost Hope #Xbox Achievement Walkthrough(2,274)
"New zero-day vulnerability identified in all versions of IE" :: Login/Create an Account :: 39 comments