What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
 
Reply to this topicStart new topic
> New 0-Day IE exploit ...
AplusWebMaster
post Nov 21 2009, 04:33 PM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,576
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

0-Day IE exploit published
- http://www.symantec.com/connect/blogs/zero...ploit-published
November 21, 2009 - "A new exploit targeting Internet Explorer was published to the BugTraq mailing list yesterday. Symantec has conducted further tests and confirmed that it affects Internet Explorer versions 6 and 7 as well. The exploit currently exhibits signs of poor reliability, but we expect that a fully-functional reliable exploit will be available in the near future... To minimize the chances of being affected by this issue, Internet Explorer users should ensure their antivirus definitions are up to date, disable JavaScript and only visit Web sites they trust until fixes are available from Microsoft."

- http://secunia.com/advisories/37448/2/
Release Date: 2009-11-23
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 6.x, Microsoft Internet Explorer 7.x ...
Solution: Disable support for active scripting for all but trusted websites...

ph34r.gif ph34r.gif

This post has been edited by AplusWebMaster: Nov 26 2009, 08:50 AM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Nov 24 2009, 07:47 AM
Post #2


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,576
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Microsoft Security Advisory (977981)
Vulnerability in Internet Explorer Could Allow Remote Code Execution
- http://forums.whatthetech.com/index.php?s=...st&p=613068
November 23, 2009

- http://www.us-cert.gov/current/#microsoft_...r_vulnerability
November 23, 2009

- http://blogs.iss.net/archive/IE%20CSS%200day.html
November 23, 2009 - "... For IE users, it is worthwhile to upgrade to IE8 if you haven't already."

ph34r.gif

This post has been edited by AplusWebMaster: Nov 24 2009, 11:36 AM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Nov 26 2009, 08:49 AM
Post #3


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,576
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

IE 0-day exploit released
- http://www.symantec.com/security_response/threatconlearn.jsp
Nov 26, 2009 - "An exploit has been released for the Metasploit framework that can be used to exploit the Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability. This exploit can leverage JavaScript heap-spray and .NET DLL memory-preparation techniques to achieve remote code execution. Customers who are prone to this issue are advised to disable JavaScript for untrusted websites. Also, setting Internet Explorer's security zone settings to high for the Internet zone will prevent the loading of .NET DLLs in Internet Explorer 7. For critical systems, consider upgrading to Internet Explorer 8, which is not vulnerable to this issue."

- http://www.pcworld.com/article/183190/atta...s_improved.html
Nov 25, 2009

ph34r.gif ph34r.gif

This post has been edited by AplusWebMaster: Nov 26 2009, 08:51 AM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Nov 26 2009, 11:22 PM
Post #4


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,576
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Microsoft Security Advisory (977981)
Vulnerability in Internet Explorer Could Allow Remote Code Execution
- http://www.microsoft.com/technet/security/...ory/977981.mspx
Updated: November 25, 2009
• V1.1 (November 25, 2009): Corrected the CVE reference, added a mitigating factor concerning Web-based attacks, and clarified the workaround involving DEP*.
* "... • Enable DEP for Internet Explorer 6 or Internet Explorer 7 via automated Microsoft Fix It. See Microsoft Knowledge Base Article 977981** to use the automated Microsoft Fix it solution to enable or disable this workaround...
Impact of workaround: Some browser extensions may not be compatible with DEP and may exit unexpectedly. If this occurs, you can disable the add-on, or revert the DEP setting using the Internet Control Panel. This is also accessible using the System Control panel..."
** http://support.microsoft.com/kb/977981

- http://www.cve.mitre.org/cgi-bin/cvename.c...e=CVE-2009-3672

- http://isc.sans.org/diary.html?storyid=7654
Last Updated: 2009-11-26 15:11:12 UTC - "... We strongly encourage all IE users to review the new information posted by MS, especially in light of workable exploits that are starting to surface on the web."
___

FIX: Microsoft Security Bulletin MS09-072 - Critical
Cumulative Security Update for Internet Explorer (976325)
- http://www.microsoft.com/technet/security/...n/MS09-072.mspx
Revisions:
• V1.0 (December 8, 2009): Bulletin published.
• V1.1 (December 9, 2009): Corrected a reference to Microsoft Knowledge Base Article 976749 in the section, Frequently Asked Questions (FAQ) Related to This Security Update. Also corrected, in the Security Update Deployment section, the registry key for verification of the update for Internet Explorer 7 for all supported x64-based editions of Windows XP.

ph34r.gif

This post has been edited by AplusWebMaster: Dec 13 2009, 05:59 AM
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

 


RSS Time is now: 22nd March 2010 - 01:59 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy