Jump to content


Welcome to iElmira

Welcome to iElmira, like most online communities you must register to view or post in our community, but don't worry this is a simple free process that requires minimal information. Take advantage of it immediately, Register Now or Sign In. You can even login in painlessly with your facebook or twitter account!
  • Start new topics and reply to others
  • Subscribe to topics and forums to get automatic updates
  • Add events to our community calendar
  • Get your own profile and make new friends
Special note to guests: We do have a completely anonymous section called iElmira Hot-Tips, where you can post your HotTip for the rest of the community, without anyone knowing who you are. Hey! Go use it now!
Oh go ahead and register, I want you to.
Photo

2 New Critical Internet Explorer Vulnerabilities


  • You cannot start a new topic
  • Please log in to reply
No replies to this topic

#1 OFFLINE   Dan

Dan

    Moderator

  • UberMember
    • Member ID: 635
  • 3,169 posts

Posted 18 June 2012 - 09:17 PM

Yeah, yeah, I know, more Internet Explorer vulnerabilities, so what's new?

Well, one of them is a newer exploit that was just recently patched, but the other is a Zero day (new exploit w/ no security patch available), and rumor has it that it is a "State Sponsored" (Pick a non-ally country that hates us) vulnerability:

CVE-2012-1889: MSXML Uninitialized Memory Corruption - This is an uninitialized memory bug found in MSXML. According to Microsoft, such a component can be loaded from either Internet Explorer and Microsoft Office. This vulnerability is rumored to be "state-sponsored", and what makes it really critical is it's still an 0-day hijacking Gmail accounts. That's right, that means if you're using Gmail as well as Internet Explorer or Microsoft Office, you're at risk. We expect this vulnerability to grow even more dangerous since there's no patch, and it's rather easy to trigger.

Though Microsoft has released some stop gap measures to deal with this, there is no word on when a patch will be available. Security experts are recommending using a different browser until a patch is released.

Exploit code for both have been released publicly and Metasploit has already created exploit modules for both and added them to their framework. So if you are familiar with the Metasploit platform you can use it to test your systems to see if they are vulnerable or not.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users