This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Exploit Posted for New IE Zero-Day

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.eweek.com/article2/0,1895,2016065,00.asp
September 14, 2006
"Security researchers in China have published detailed exploit code for a new zero-day vulnerability in Microsoft's dominant Internet Explorer browser. The exploit, which was posted to XSec.org and Milw0rm.com Web sites, could be easily modified to launch code execution attacks without any user action on fully patched Windows machines. A spokesman for the MSRC (Microsoft Security Response Center) said the company is investigating the latest warning, which adds to a list of known high-risk vulnerabilities that remain unpatched… "It's worth knowing about and monitoring, in case someone improves it. But it's not a huge threat as it stands," Thompson said…"

- http://secunia.com/advisories/21910/
Last Update: 2006-09-15
Critical: Extremely critical

> http://www.microsoft.com/technet/security/…ory/925444.mspx

:ph34r:
FYI…

MSIE DirectAnimation ActiveX 0-day update
- http://isc.sans.org/diary.php?storyid=1705
Last Updated: 2006-09-15 14:01:55 UTC (…Version: 3…)
"Microsoft released a security advisory regarding the 0-day we reported on earlier.
Timeline:
* Aug 28th: 1st exploit released publicly
* Aug 29th: CVE-2006-4446 assigned - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4446
* Sept 13th: 2nd exploit released publicly
* Sept 13th: CVE-2006-4777 assigned - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4777
* Sept 14th: Microsoft Security Advisory (925444) released
Workarounds:
* Use an alternate browser (see also diversity*)
* Disable ActiveX scripting in MSIE
* Modify the ACL on daxctle.ocx to remove rights to use it
* Set the KillBit for "{D7A7D7C3-D47F-11D0-89D3-00A0C90833E6}"
* Make MSIE prompt before executing ActiveX
Please note that windowsupdate needs an ActiveX enabled browser, but you can do that with settings to the security zones and trusting Microsoft.
Please note that the Outlook family is affected as well but that the default settings will typically mitigate much of the risk. That is as long as nobody or nothing has modified the settings …"
* http://isc.sans.org/diary.php?storyid=1550

> http://www.kb.cert.org/vuls/id/377369

:oops: