Jump to content

Zero Day Exploit


nellie2
 Share

Recommended Posts

Secunia Research has discovered a vulnerability in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error in the processing of the "createTextRange()" method call applied on a radio button control. This can be exploited by e.g. a malicious web site to corrupt memory in a way, which allows the program flow to be redirected to the heap. Successful exploitation allows execution of arbitrary code. NOTE: Exploit code is publicly available. The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2. The vulnerability has also been confirmed in Internet Explorer 7 Beta 2 Preview (January edition). Other versions may also be affected. Solution: Disable Active Scripting support.

source

This is serious, you are vulnerable to this exploit even if you use a different browser like Firefox, IE can still be launched to allow this attack to take place.

Advice;

Be careful about the sites you visit, stick to your tried and tested ones for now

Disable active scripting, doing this may effect the way some websites behave. So add your favourite and regular sites to your trusted zone, that way they will work properly. See here for tutorial

Link to comment
Share on other sites

There is a date of 22-11-2005 on your link, nel. Does this mean this exploit has been around since then and no-one (i.e Secunia) has taken any notice until now?

Have there been any instances of this exploit occurring?

It always worries me that the mere publication of information like this by concerns such as Secunia will encourage the less scrupulous amongst us to work even harder to produce whatever is required to cuff up people's machines. Why, when they discover these nasties, don't they have a quiet word with Mr Gates and his crew and work towards a remedy behind the scenes?

I carried out the changes in the link to ZDNet. Not a single web page that I tried to open did so correctly. I've changed the settings back. Seems like you need to add your trusted pages before trying to open but, if you do that, how do you access new pages for a one-off viewing? I'm not going to go through the procedure of adding every web page I ever want to look at into a special little box just so I can look as it for a couple of seconds.

Or have it got it wrong?

Link to comment
Share on other sites

Hmmm... as I thought would happen:

Folks, as Lorna predicted yesterday, it didn't take long for the exploits to appear for that IE vulnerability.

From the Calendar of Updates given by nel. I suspect these are entirely a result of the publicity.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy