Breaking News

Akasa Unleashes Six New Low-Profile CPU Coolers Up to 165W TDP Cooling in Compact Form Factors SWIT announces Powercell Battery Series for Sony, Canon, Nikon, and Fujifilm Cameras TerraMaster launces D1 SSD Pro 80Gbps Thunderbolt 5 Enclosure PROGRADE DIGITAL ANNOUNCES SPACE ACT AGREEMENT WITH NASA FOR ARTEMIS LUNAR MISSIONS EnGenius Unveils Cloud-Managed ECW536S Wi-Fi 7 with 24/7 AirGuard Security

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Microsoft Confirms Zero-Day Exploit For Internet Explorer

Microsoft Confirms Zero-Day Exploit For Internet Explorer

Enterprise & IT Nov 24,2009 0

A new exploit targeting Internet Explorer was announced by Microsoft yesterday, and Microsoft has released an advisory with information and workarounds. According to Microsoft's investigation so far, Internet Explorer 5.01 Service Pack 4 and Internet Explorer 8 on all supported versions of Microsoft Windows are not affected, and that Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6 and Internet Explorer 7 on supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 are affected.

The vulnerability exists as an invalid pointer reference of Internet Explorer. It is possible under certain conditions for a CSS/Style object to be accessed after the object is deleted. In a specially-crafted attack, Internet Explorer attempting to access a freed object can lead to running attacker-supplied code.

Security firm Symantec has also confirmed that it affects Internet Explorer versions 6 and 7.

"The exploit currently exhibits signs of poor reliability, but we expect that a fully-functional reliable exploit will be available in the near future. When this happens, attackers will have the ability to insert the exploit into Web sites, infecting potential visitors. For an attacker to launch a successful attack, they must lure victims to their malicious Web page or a Web site they have compromised. In both cases, the attack requires JavaScript to exploit Internet Explorer," Symantec said.

The security firm suggests Internet Explorer users to ensure their antivirus definitions are up to date, disable JavaScript and only visit Web sites they trust until fixes are available from Microsoft.

On completion of Microsoft's investigation, the conmpany may include providing a solution through its monthly security update release process, or an out-of-cycle security update.

Tags: MicrosoftVirus
Previous Post
Samsung Announces Special Prices For HDTVs
Next Post
Lite-On Releases New LabelTag Drive

Related Posts

  • Snapdragon X Series is the Exclusive Platform to Power the Next Generation of Windows PCs with Copilot+ Today

  • Activision Blizzard King to Team Xbox

  • NVIDIA Studio Lineup Adds RTX-Powered Microsoft Surface Laptop Studio 2

  • Samsung and Microsoft Unveil First On-Device Attestation Solution for Enterprise

  • Introducing Xbox Game Pass Core, Coming This September

  • Announcing the next wave of AI innovation with Microsoft Bing and Edge

  • Microsoft Announces Security Copilot AI

  • Microsoft breaks new ground in healthcare with the next evolution of AI

Latest News

Akasa Unleashes Six New Low-Profile CPU Coolers Up to 165W TDP Cooling in Compact Form Factors
Cooling Systems

Akasa Unleashes Six New Low-Profile CPU Coolers Up to 165W TDP Cooling in Compact Form Factors

SWIT announces Powercell Battery Series for Sony, Canon, Nikon, and Fujifilm Cameras
Cameras

SWIT announces Powercell Battery Series for Sony, Canon, Nikon, and Fujifilm Cameras

TerraMaster launces D1 SSD Pro 80Gbps Thunderbolt 5 Enclosure
Enterprise & IT

TerraMaster launces D1 SSD Pro 80Gbps Thunderbolt 5 Enclosure

PROGRADE DIGITAL ANNOUNCES SPACE ACT AGREEMENT WITH NASA FOR ARTEMIS LUNAR MISSIONS
Cameras

PROGRADE DIGITAL ANNOUNCES SPACE ACT AGREEMENT WITH NASA FOR ARTEMIS LUNAR MISSIONS

EnGenius Unveils Cloud-Managed ECW536S Wi-Fi 7 with 24/7 AirGuard Security
Enterprise & IT

EnGenius Unveils Cloud-Managed ECW536S Wi-Fi 7 with 24/7 AirGuard Security

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed