Wednesday, September 20, 2006

More on zero day IE exploit

Based on our investigation, this exploit code could allow an attacker to execute arbitrary code on the user's system. Thus far the attacks appear targeted and very limited.

Just for fun, Sunbelt researcher Adam Thomas (who discovered the VML exploit yesterday) has cataloged what is installed with one installation he observed. Epic quantities of junk.

Microsoft has tested the following workaround. While this workaround will not correct the underlying vulnerability, it helps block known attack vectors. When a workaround reduces functionality, it is identified in the following section.

Read the article HERE.


Post a Comment

<< Home