Make smart financial decisions with DailyFinance

Microsoft warns of zero-day IE exploit

Well, we've all talked about the zero-day exploit for a long time. Seems it has arrived According to an advisory issued by Microsoft last night and report at eWEEK this morning, a newly discovered vulnerability in Internet Explorer has already been exploited and code is in the wild. This is serious enough that Microsoft has already released a workaround and seems to be leaning toward an out-of-cycle patch as soon as it's been developed.

From the eWEEK report:

"Microsoft late Thursday issued an advisory with pre-patch workarounds to counter the public release of a zero-day exploit targeting users of its Internet Explorer browser.

The release of the advisory comes less than 24 hours after the FrSIRT (French Security Incident Response Team) published a proof-of-concept exploit that could be used by malicious hackers to target IE users.

There is no patch available for the vulnerability and, because exploit code has already been released, incident handlers at the SANS ISC (Internet Storm Center) believe a widespread attack is very likely.

The software giant has also activated an RSS feed for its security advisories to help customers keep track of threat warnings."

Subscribed.

UPDATE: SANS has posted both a command-line and GUI tool to set a "kill bit" to close the vulnerability. The SANS page warns that this workaround t may impact some legitimate ActiveX controls that call the affected .dll file. The change is easily reversible.

Developer Tools
.Net Framework (7)
Alternatives (0)
Dev Tools - General (6)
Visual Studio (6)
Win32 (0)
WinFX (0)
Web Offerings
Gadgets (1)
Internet Explorer (6)
MSN (8)
Office Live (1)
Windows Live (10)
Windows
2000 (0)
Media Center Edition (MCE) (0)
Mobile (5)
Tablet PC Edition (7)
Vienna (0)
Vista (43)
Windows - General (62)
XP (29)
Gaming
PC (3)
XBOX (2)
XBOX 360 (3)
How-To
General How-To's (3)
Tips and Tricks (4)
Tutorials (0)
Office
Access (0)
Excel (1)
FrontPage (1)
InfoPath (1)
Office - General (11)
OneNote (3)
Outlook (6)
PowerPoint (1)
Publisher (0)
Word (2)
Server Systems
BizTalk (0)
Exchange Server (1)
Live Communication Server (0)
Servers - General (0)
Speech Server (0)
SQL Server (0)
Windows Server (1)
Microsoft
Origami Project (16)
Competition (15)
Financial (2)
Legal Issues (7)
News and Info (75)
Trends and Buzz (70)

RESOURCES

RSS NEWSFEEDS

Powered by Blogsmith

Other Weblogs Inc. Network blogs you might be interested in: